0ang3el/unsafe-xmlrpc

0ang3el/unsafe-xmlrpc

Releases0
Stars4

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.