imPC@ndo IT

Tracker / CVE-2024-47554

CVE-2024-47554

Medium 4.3

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

Affected products and versions

apache commons_io · 2.0 → 2.14.0
netapp active_iq_unified_manager
netapp bluexp
netapp e-series_santricity_unified_manager
netapp e-series_santricity_web_services_proxy
netapp ontap_tools
netapp santricity_storage_plugin
netapp snapcenter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References