In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
References
Link | Resource |
---|---|
https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6 | Mailing List Vendor Advisory |
http://www.openwall.com/lists/oss-security/2024/07/18/4 | |
https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6 | Mailing List Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240808-0008/ |
Configurations
History
No history.
Information
Published : 2024-07-19 09:15
Updated : 2024-11-21 09:32
NVD link : CVE-2024-41172
Mitre link : CVE-2024-41172
CVE.ORG link : CVE-2024-41172
JSON object : View
Products Affected
apache
- cxf
CWE
CWE-401
Missing Release of Memory after Effective Lifetime