« Volver al listado

CVE-2025-32952

Estado: AnalizadaMedia (6.5)—

Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32952",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32952",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-24T19:56:32.907417Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "jmix-framework",
          "product": "jmix",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.0.0, < 1.6.2"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, < 2.4.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-22T18:16:00.097",
  "references": [
    {
      "url": "https://docs.jmix.io/jmix/files-vulnerabilities.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://docs.jmix.io/jmix/files-vulnerabilities.html#disable-files-endpoint-in-jmix-application",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/6a66aa3adb967159a30d703e80403406f4c8f7a2",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/c589ef4e2b25620770b8036f4ad05f1a6250cb6a",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/cc97e6ff974b9e7af8160fab39cc5866169daa37",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/commit/f4e6fb05bd245cf36f3e9319aaa0fcd540d024aa",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/issues/3804",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/issues/3836",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jmix-framework/jmix/security/advisories/GHSA-f3gv-cwwh-758m",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website."
    },
    {
      "lang": "es",
      "value": "Jmix es un conjunto de librerías y herramientas para acelerar el desarrollo de aplicaciones centradas en datos en Spring Boot. En las versiones 1.0.0 a 1.6.1 y 2.0.0 a 2.3.4, la implementación del almacenamiento local de archivos no restringe el tamaño de los archivos subidos. Un atacante podría aprovechar esta situación subiendo archivos excesivamente grandes, lo que podría provocar que el servidor se quede sin espacio y devuelva un error HTTP 500, lo que resulta en una denegación de servicio. Este problema se ha corregido en las versiones 1.6.2 y 2.4.0. Se ofrece un workaround en el sitio web de documentación de Jmix."
    }
  ],
  "lastModified": "2026-06-17T09:12:51.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:haulmont:cuba_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4144D951-290E-4CDD-88B0-F4052FD28B7F",
              "versionEndExcluding": "7.2.23",
              "versionStartIncluding": "6.2.0"
            },
            {
              "criteria": "cpe:2.3:a:haulmont:cuba_rest_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9943C493-5789-4D32-A280-7BA564818C8A",
              "versionEndExcluding": "7.2.7",
              "versionStartIncluding": "7.1.1"
            },
            {
              "criteria": "cpe:2.3:a:haulmont:jmix_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A877F67E-4952-4984-8F29-A5DFD0E3090A",
              "versionEndExcluding": "1.6.2",
              "versionStartIncluding": "1.0.0"
            },
            {
              "criteria": "cpe:2.3:a:haulmont:jmix_framework:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "266AE114-6141-48C3-BCBC-33C47FBE0B89",
              "versionEndExcluding": "2.4.0",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:haulmont:jpa_web_api:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCA5975A-4E12-4D55-A93B-486BC1D9F219",
              "versionEndExcluding": "1.1.1",
              "versionStartIncluding": "1.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}