Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvm3-cfvj-gxqq

Опубликовано: 21 дек. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

High severity vulnerability that affects commons-fileupload:commons-fileupload

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Ссылки

Пакеты

Наименование

commons-fileupload:commons-fileupload

maven
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

EPSS

Процентиль: 98%
0.35927
Средний

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 10 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
redhat
около 10 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
nvd
около 10 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
debian
около 10 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, a ...

CVSS3: 7.3
fstec
около 10 лет назад

Уязвимость библиотеки Сommons FileUpload, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.35927
Средний

7.5 High

CVSS3

Дефекты

CWE-20