Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-32952


Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.


Published

2025-04-22T18:16:00.097

Last Modified

2025-12-31T15:55:53.993

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-770

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haulmont cuba_platform < 7.2.23 Yes
Application haulmont cuba_rest_api < 7.2.7 Yes
Application haulmont jmix_framework < 1.6.2 Yes
Application haulmont jmix_framework < 2.4.0 Yes
Application haulmont jpa_web_api < 1.1.1 Yes

References