Jmix is a set of libraries and tools to speed up Spring Boot data-centric application development. In versions 1.0.0 to 1.6.1 and 2.0.0 to 2.3.4, the local file storage implementation does not restrict the size of uploaded files. An attacker could exploit this by uploading excessively large files, potentially causing the server to run out of space and return HTTP 500 error, resulting in a denial of service. This issue has been patched in versions 1.6.2 and 2.4.0. A workaround is provided on the Jmix documentation website.
References
Configurations
Configuration 1 (hide)
|
History
31 Dec 2025, 15:55
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Haulmont cuba Platform
Haulmont cuba Rest Api Haulmont Haulmont jmix Framework Haulmont jpa Web Api |
|
| CPE | cpe:2.3:a:haulmont:jpa_web_api:*:*:*:*:*:*:*:* cpe:2.3:a:haulmont:cuba_rest_api:*:*:*:*:*:*:*:* cpe:2.3:a:haulmont:cuba_platform:*:*:*:*:*:*:*:* cpe:2.3:a:haulmont:jmix_framework:*:*:*:*:*:*:*:* |
|
| References | () https://docs.jmix.io/jmix/files-vulnerabilities.html - Vendor Advisory | |
| References | () https://docs.jmix.io/jmix/files-vulnerabilities.html#disable-files-endpoint-in-jmix-application - Vendor Advisory | |
| References | () https://github.com/jmix-framework/jmix/commit/6a66aa3adb967159a30d703e80403406f4c8f7a2 - Patch | |
| References | () https://github.com/jmix-framework/jmix/commit/c589ef4e2b25620770b8036f4ad05f1a6250cb6a - Patch | |
| References | () https://github.com/jmix-framework/jmix/commit/cc97e6ff974b9e7af8160fab39cc5866169daa37 - Patch | |
| References | () https://github.com/jmix-framework/jmix/commit/f4e6fb05bd245cf36f3e9319aaa0fcd540d024aa - Patch | |
| References | () https://github.com/jmix-framework/jmix/issues/3804 - Issue Tracking | |
| References | () https://github.com/jmix-framework/jmix/issues/3836 - Issue Tracking | |
| References | () https://github.com/jmix-framework/jmix/security/advisories/GHSA-f3gv-cwwh-758m - Patch, Vendor Advisory |
27 May 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Apr 2025, 14:08
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
22 Apr 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-22 18:16
Updated : 2025-12-31 15:55
NVD link : CVE-2025-32952
Mitre link : CVE-2025-32952
CVE.ORG link : CVE-2025-32952
JSON object : View
Products Affected
haulmont
- cuba_rest_api
- cuba_platform
- jpa_web_api
- jmix_framework
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
