QID 994949
Date Published: 2023-08-22
QID 994949: Java (Maven) Security Update for org.apache.xmlrpc:xmlrpc-common (GHSA-r2pg-w96p-pcpj)
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-r2pg-w96p-pcpj for updates and patch information.
Vendor References
- GHSA-r2pg-w96p-pcpj -
github.com/advisories/GHSA-r2pg-w96p-pcpj
CVEs related to QID 994949
Software Advisories
| Advisory ID | Software | Component | Link |
|---|