CVE-2025-32952
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: security-advisories@github.com (Secondary)
Description
Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.
Affected (5)
Products: Haulmont: Cuba Platform, Cuba Rest Api, Jmix Framework, Jpa Web Api
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.2.0 to 7.2.23 | |
| From 7.1.1 to 7.2.7 | |
| From 1.0.0 to 1.6.2 | |
| From 1.0.0 to 1.1.1 |
References (9)
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
PatchVendor Advisory
Timeline
No history available yet.