Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fvm3-cfvj-gxqq

Опубликовано: 21 дек. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

High severity vulnerability that affects commons-fileupload:commons-fileupload

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Ссылки

Пакеты

Наименование

commons-fileupload:commons-fileupload

maven
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

EPSS

Процентиль: 97%
0.40246
Средний

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 9 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
redhat
почти 9 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
nvd
почти 9 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

CVSS3: 7.5
debian
почти 9 лет назад

The MultipartStream class in Apache Commons Fileupload before 1.3.2, a ...

fstec
почти 9 лет назад

Уязвимость библиотеки Сommons FileUpload, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 97%
0.40246
Средний

7.5 High

CVSS3

Дефекты

CWE-20