Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-24998

Опубликовано: 20 фев. 2023
Источник: redhat
CVSS3: 6.5
EPSS Средний

Описание

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

A flaw was found in Apache Commons FileUpload, where it does not limit the number of parts being processed in a request. This issue may allow an attacker to use a malicious upload or series of uploads to trigger a denial of service. While Red Hat Satellite relies upon Apache Tomcat, it does not directly ship it. Tomcat is shipped with Red Hat Enterprise Linux and consumed by the Candlepin component of Satellite. Red Hat Satellite users are therefore advised to check the impact state of Red Hat Enterprise Linux, since any necessary fixes will be distributed through the platform.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2log4jNot affected
A-MQ Clients 2tomcatNot affected
Migration Toolkit for Applications 6org.keycloak-keycloak-parentWill not fix
Red Hat AMQ Broker 7artemisNot affected
Red Hat build of Debezium 1commons-fileuploadWill not fix
Red Hat Data Grid 8commons-fileuploadWill not fix
Red Hat Data Grid 8tomcatWill not fix
Red Hat Decision Manager 7drools-coreOut of support scope
Red Hat Decision Manager 7tomcatOut of support scope
Red Hat Enterprise Linux 6tomcat6Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2172298FileUpload: FileUpload DoS with excessive parts

EPSS

Процентиль: 97%
0.41119
Средний

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
nvd
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
debian
больше 2 лет назад

Apache Commons FileUpload before 1.5 does not limit the number of requ ...

suse-cvrf
около 2 лет назад

Security update for apache-commons-fileupload

suse-cvrf
больше 2 лет назад

Security update for tomcat

EPSS

Процентиль: 97%
0.41119
Средний

6.5 Medium

CVSS3