Описание
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | tomcat5 | Not affected | ||
Red Hat Enterprise Linux 6 | tomcat6 | Not affected | ||
Red Hat JBoss Data Grid 6 | jbossweb | Affected | ||
Red Hat JBoss Data Virtualization 6 | jbossweb | Affected | ||
Red Hat JBoss Enterprise Application Platform 4 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Application Platform 5 | jbossweb | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | tomcat5 | Not affected | ||
Red Hat JBoss Enterprise Web Server 1 | tomcat6 | Not affected | ||
Red Hat JBoss Enterprise Web Server 2 | tomcat6 | Not affected | ||
Red Hat JBoss Enterprise Web Server 3 | tomcat7 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
4.3 Medium
CVSS2
Связанные уязвимости
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
The MultipartStream class in Apache Commons Fileupload before 1.3.2, a ...
High severity vulnerability that affects commons-fileupload:commons-fileupload
Уязвимость библиотеки Сommons FileUpload, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3
4.3 Medium
CVSS2