CVE-2023-24998
20.02.2023, 16:15
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the
new configuration option (FileUploadBase#setFileCountMax) is not
enabled by default and must be explicitly configured.Enginsight| Vendor | Product | Version |
|---|---|---|
| apache | commons_fileupload | 1.0 ≤ 𝑥 < 1.5 |
| apache | commons_fileupload | 1.0:beta |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libcommons-fileupload-java |
| ||||||||||||
| tomcat10 |
| ||||||||||||
| tomcat9 |
|
Ubuntu Releases
References