4.3
CVE-2024-54016
- EPSS 0.63%
- Veröffentlicht 20.03.2025 08:59:26
- Zuletzt bearbeitet 01.04.2025 20:35:54
- Erkennungen
compression bomb attack in Apache Seata Server
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.63% | 0.471 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
https://lists.apache.org/thread/grn0x8tmssx07qc9z50lwgmrkwzrrhzg
http://www.openwall.com/lists/oss-security/2025/03/19/6