Bug 2339095 (CVE-2025-23184)
| Summary: | CVE-2025-23184 org.apache.cxf: Apache CXF: Denial of Service vulnerability with temporary files | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | anstephe, aschwart, asoldano, avibelli, bbaranow, bgeorges, bihu, bmaxwell, boliveir, brian.stansberry, cdewolf, chazlett, chfoley, clement.escoffier, cmiranda, dandread, darran.lofthouse, dhanak, dkreling, dosoudil, drichtar, fjuma, fmariani, fmongiar, gmalinko, gsmet, ibek, istudens, ivassile, iweiss, janstey, jcantril, jkoops, jmartisk, jnethert, jpoth, jrokos, jscholz, kverlaen, lgao, lthon, manderse, mnovotny, mosmerov, mposolda, msochure, msvehla, nwallace, olubyans, pcongius, pdelbell, pdrozd, peholase, pesilva, pgallagh, pjindal, pmackay, probinso, pskopek, rguimara, rmartinc, rojacob, rowaters, rruss, rstancel, rstepani, rsvoboda, sausingh, sbiarozk, smaestri, ssilvert, sthorger, swoodman, tcunning, tom.jenkinson, tqvarnst, vmuzikar, wfink, yfang |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in Apache CXF. In some edge cases with large data stream caching, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system and trigger a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-01-21 10:01:10 UTC
This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 Via RHSA-2025:10453 https://access.redhat.com/errata/RHSA-2025:10453 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 Via RHSA-2025:10452 https://access.redhat.com/errata/RHSA-2025:10452 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 8.0.8 Via RHSA-2025:10459 https://access.redhat.com/errata/RHSA-2025:10459 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 Via RHSA-2025:10926 https://access.redhat.com/errata/RHSA-2025:10926 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 Via RHSA-2025:10925 https://access.redhat.com/errata/RHSA-2025:10925 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 Via RHSA-2025:10924 https://access.redhat.com/errata/RHSA-2025:10924 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7.4.23 Via RHSA-2025:10931 https://access.redhat.com/errata/RHSA-2025:10931 This issue has been addressed in the following products: Red Hat JBoss Enterprise Application Platform 7 Via RHSA-2025:10931 https://access.redhat.com/errata/RHSA-2025:10931 |