Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-47554


Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.


Published

2024-10-03T12:15:02.613

Last Modified

2025-07-10T21:10:32.113

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache commons_io < 2.14.0 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp bluexp - Yes
Application netapp e-series_santricity_unified_manager - Yes
Application netapp e-series_santricity_web_services_proxy - Yes
Application netapp ontap_tools 9 Yes
Application netapp ontap_tools 10 Yes
Application netapp santricity_storage_plugin - Yes
Application netapp snapcenter - Yes

References