Description
The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5067 | The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes. |
Github GHSA |
GHSA-r2pg-w96p-pcpj | ws-xmlrpc DoS Vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T00:46:40.199Z
Reserved: 2016-05-24T00:00:00.000Z
Link: CVE-2016-5004
No data.
Status : Modified
Published: 2017-06-06T18:29:00.450
Modified: 2026-05-13T00:24:29.033
Link: CVE-2016-5004
OpenCVE Enrichment
No data.
EUVD
Github GHSA