Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-24998

Опубликовано: 20 фев. 2023
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.

Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.5 (исключая)
cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.41119
Средний

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 6.5
redhat
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
debian
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of requ ...

suse-cvrf
около 2 лет назад

Security update for apache-commons-fileupload

suse-cvrf
больше 2 лет назад

Security update for tomcat

EPSS

Процентиль: 97%
0.41119
Средний

7.5 High

CVSS3

Дефекты

CWE-770