CVE FIX - upgrade Apache CXF

Assignee

Reporter

Sprint

Description

CVE-2025-23184

A potential denial of service vulnerability is present in versions of Apache CXF before 3.5.10, 3.6.5 and 4.0.6. In some edge cases, the CachedOutputStream instances may not be closed and, if backed by temporary files, may fill up the file system (it applies to servers and clients).

Affected submodules

  • cxf-rt-ws-policy

  • cxf-rt-ws-addr

  • cxf-rt-transports-http

  • cxf-rt-frontend-simple

  • cxf-rt-frontend-jaxws

  • cxf-rt-databinding-jaxb

  • cxf-rt-bindings-xml

  • cxf-rt-bindings-soap

All of them are reported twice in our security job – version 4.0.5 in worker and version 3.6.4 in cloveretl.initiate.engine.

Steps to reproduce

None

relates to

Activity

Fixed

Details

Priority

Fix versions

QA Testing

UNDECIDED

Created February 12, 2025 at 8:50 AM
Updated March 25, 2025 at 12:31 PM
Resolved February 21, 2025 at 7:10 AM