CVEFinder.io

CVE-2024-47554

🔶 medium
🔍 Scan for this CVE
Summary

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0 or later, which fixes the issue.

CVSS Score
4.3
Medium
EPSS Score
0.2
Exploit Probability
Published Date
2024-10-03
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 5.4% of all 329,456 vulnerabilities in our database.

#311,645
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Oct 3, 2024
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
CodeQL (tool)
SSVC data provided by CISA
Last Modified 2025-07-10
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CWE IDs (Weakness Types)

📦 Affected Products 9

🔗 References 3

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-27820 ⚠️ high 7.5 0.1 A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host na... 2025-04-24
CVE-2025-21583 🔶 medium 4.9 0.1 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affecte... 2025-04-15
CVE-2025-30722 🔶 medium 5.3 0.1 Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are a... 2025-04-15
CVE-2025-31672 🔶 medium 5.3 1.0 Improper Input Validation vulnerability in Apache POI. The issue affects the parsing of OOXML format files like xlsx, do... 2025-04-09
CVE-2025-26512 ⛔ critical 9.9 0.1 SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated Sna... 2025-03-24
CVE-2024-56171 ⚠️ high 7.8 0.1 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID... 2025-02-18
These CVEs affect the same products