CVE-2022-37034
01.02.2023, 23:15
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.Enginsight
Vendor | Product | Version |
---|---|---|
dotcms | dotcms | 𝑥 < 21.06.12 |
dotcms | dotcms | 5.2.0 ≤ 𝑥 < 22.10 |
dotcms | dotcms | 22.03 ≤ 𝑥 < 22.03.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration