CVE-2024-41172
CVSS V2 None
CVSS V3 None
Description
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventually causing the application to run out of memory
Overview
- CVE ID
- CVE-2024-41172
- Assigner
- apache
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-19T08:50:43.766Z
- Last Modified Date
- 2024-07-19T08:50:43.766Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://lists.apache.org/thread/n2hvbrgwpdtcqdccod8by28ynnolybl6 | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-41172 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41172 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-20 13:04:17 | Added to TrackCVE |