Uncontrolled Resource Consumption Vulnerability in Apache Commons IO
CVE-2024-47554
4.3MEDIUM
What is CVE-2024-47554?
The vulnerability in the org.apache.commons.io.input.XmlStreamReader class can lead to excessive CPU resource consumption due to the processing of specially crafted input. This behavior may create significant performance issues, particularly when handling untrusted XML data. To mitigate this risk, it is recommended that users upgrade to Apache Commons IO version 2.14.0 or later, where this issue has been addressed. Proper security measures should be considered when dealing with external inputs to prevent potential exploitation.
Affected Version(s)
Apache Commons IO 2.0 < 2.14.0