Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02159-1

Опубликовано: 27 июн. 2025
Источник: suse-cvrf

Описание

Security update for apache-commons-fileupload

This update for apache-commons-fileupload fixes the following issues: Upgrade to upstream version 1.6.0

  • CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657).

Full changelog:

https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0

Список пакетов

Container suse/manager/5.0/x86_64/server:latest
apache-commons-fileupload-1.6.0-150200.3.12.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2
apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-GCE
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Enterprise Storage 7.1
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP6
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Module for Web and Scripting 15 SP7
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP3-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP4-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server 15 SP5-LTSS
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
apache-commons-fileupload-1.6.0-150200.3.12.1
SUSE Manager Server 4.3
apache-commons-fileupload-1.6.0-150200.3.12.1
openSUSE Leap 15.6
apache-commons-fileupload-1.6.0-150200.3.12.1
apache-commons-fileupload-javadoc-1.6.0-150200.3.12.1

Описание

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.


Затронутые продукты
Container suse/manager/5.0/x86_64/server:latest:apache-commons-fileupload-1.6.0-150200.3.12.1
Container suse/multi-linux-manager/5.1/x86_64/server:latest:apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-Azure:apache-commons-fileupload-1.6.0-150200.3.12.1
Image SLES15-SP4-Manager-Server-4-3-BYOS-EC2:apache-commons-fileupload-1.6.0-150200.3.12.1

Ссылки