CVE-2023-24998

🟡 Monitoruj

Brak limitu części żądania w Apache Commons FileUpload umożliwia atak DoS przez złośliwe przesyłki.

CVSS
7.5
EPSS
48.8%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)48.8%
Opublikowano (NVD)2023-02-20 16:15:10 UTC
Ostatnia modyfikacja (NVD)2026-10-07 17:16:43 UTC
Referencje