Impact
Apache Neethi fetches remote policy references but only limits time on each read operation. A malicious or slow responding server can deliver data so slowly that the client thread remains blocked indefinitely, tying up system resources and effectively denying service to legitimate requests. The vulnerability does not expose sensitive data or allow code execution; its primary consequence is availability disruption.
Affected Systems
The issue affects Apache Neethi deployments that rely on remote policy references. All versions prior to the released fix in 3.2.4 are vulnerable; no specific minor versions were listed as unaffected.
Risk and Exploitability
The exploit requires an attacker to control or induce a slow responding policy server that the client contacts. Because the CVSS score is not provided and EPSS is unavailable, the severity cannot be quantified, but the denial-of-service impact could be significant in environments where policy fetching is frequent. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known.
OpenCVE Enrichment