CVE-2023-24998
20.02.2023, 16:15
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.Enginsight
Vendor | Product | Version |
---|---|---|
apache | commons_fileupload | 1.0 ≤ 𝑥 < 1.5 |
apache | commons_fileupload | 1.0:beta |
debian | debian_linux | 9.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libcommons-fileupload-java |
| ||||||||||||
tomcat10 |
| ||||||||||||
tomcat9 |
|

Ubuntu Releases
References