Skip to main content

Improper Handling of Highly Compressed Data (Data Amplification)

CVE-2024-54016

Severity Medium
Score 4.3/10

Summary

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating) versions through 2.2.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • LOW

CWE-409 - Improper Handling of Highly Compressed Data (Data Amplification)

The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Advisory Timeline

  • Published