CVE-2023-24998
🟡 Monitoruj
Brak limitu części żądania w Apache Commons FileUpload umożliwia atak DoS przez złośliwe przesyłki.
CVSS
7.5
EPSS
48.8%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 48.8% |
| Opublikowano (NVD) | 2023-02-20 16:15:10 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 17:16:43 UTC |
Referencje
- http://www.openwall.com/lists/oss-security/2023/05/22/1 ([email protected]) [Mailing List]
- https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy ([email protected]) [Mailing List, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html ([email protected]) [Third Party Advisory]
- https://security.gentoo.org/glsa/202305-37 ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2023/dsa-5522 ([email protected]) [Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html (af854a3a-2127-422b-91ae-364da2661108)
- https://security.netapp.com/advisory/ntap-20230302-0013/ (af854a3a-2127-422b-91ae-364da2661108)
- https://security.netapp.com/advisory/ntap-20241108-0002/ (af854a3a-2127-422b-91ae-364da2661108)