Описание
Security update for apache-commons-fileupload
This update for apache-commons-fileupload fixes the following issues: Upgrade to upstream version 1.6.0
- CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657).
Full changelog:
https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0
Список пакетов
Container suse/manager/5.0/x86_64/server:latest
apache-commons-fileupload-1.6.0-150200.3.12.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Enterprise Storage 7.1
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP6
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP3-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP4-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP5-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Manager Server 4.3
apache-commons-fileupload-1.6.0-150200.3.12.1
openSUSE Leap 15.6
apache-commons-fileupload-1.6.0-150200.3.12.1
apache-commons-fileupload-javadoc-1.6.0-150200.3.12.1
Ссылки
- Link for SUSE-SU-2025:02159-1
- E-Mail link for SUSE-SU-2025:02159-1
- SUSE Security Ratings
- SUSE Bug 1244657
- SUSE CVE CVE-2025-48976 page
Описание
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:apache-commons-fileupload-1.6.0-150200.3.12.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest:apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:apache-commons-fileupload-1.6.0-150200.3.12.1
Ссылки
- CVE-2025-48976
- SUSE Bug 1244657