Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hfrx-6qgj-fp6c

Опубликовано: 20 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Commons FileUpload denial of service vulnerability

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

Пакеты

Наименование

commons-fileupload:commons-fileupload

maven
Затронутые версииВерсия исправления

< 1.5

1.5

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.5

10.1.5

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.0-M5

11.0.0-M5

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 8.5.85, < 8.5.88

8.5.88

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 9.0.0-M1, < 9.0.71

9.0.71

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.5

10.1.5

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.0-M5

11.0.0-M5

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.5.85, < 8.5.88

8.5.88

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.0-M1, < 9.0.71

9.0.71

EPSS

Процентиль: 97%
0.41119
Средний

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 6.5
redhat
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
nvd
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
debian
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of requ ...

suse-cvrf
около 2 лет назад

Security update for apache-commons-fileupload

EPSS

Процентиль: 97%
0.41119
Средний

7.5 High

CVSS3

Дефекты

CWE-770