CVE-2023-24998
Summary
| CVE | CVE-2023-24998 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-20 16:15:00 UTC |
| Updated | 2023-10-13 16:15:00 UTC |
| Description | Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the
new configuration option (FileUploadBase#setFileCountMax) is not
enabled by default and must be explicitly configured. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5522-1 tomcat9 |
MISC |
www.debian.org |
|
| [SECURITY] [DLA 3617-1] tomcat9 security update |
MISC |
lists.debian.org |
|
| oss-security - CVE-2023-28709 Apache Tomcat - Fix for CVE-2023-24998 was
incomplete |
MISC |
www.openwall.com |
|
| Apache Tomcat: Multiple Vulnerabilities (GLSA 202305-37) — Gentoo security |
MISC |
security.gentoo.org |
|
| lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy |
MISC |
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150676 Oracle WebLogic Server Multiple Vulnerabilities (APR-2023)
- 150687 Apache Tomcat FileUpload Denial Of Service (DoS) Vulnerability (CVE-2023-24998)
- 161103 Oracle Enterprise Linux Security Update for tomcat (ELSA-2023-6570)
- 161166 Oracle Enterprise Linux Security Update for tomcat (ELSA-2023-7065)
- 184748 Debian Security Update for tomcat9libcommons-fileupload-javatomcat10 (CVE-2023-24998)
- 20341 Oracle Database 19c Critical Patch Update - April 2023
- 20342 Oracle Database 21c Critical Patch Update - April 2023
- 20343 Oracle Database 19c Critical OJVM Patch Update - April 2023
- 20354 Oracle Database 19c Critical Patch Update - July 2023
- 20355 Oracle Database 21c Critical Patch Update - July 2023
- 20356 Oracle Database 19c Critical OJVM Patch Update - July 2023
- 242102 Red Hat Update for red hat jboss web server 5.7.4 (RHSA-2023:4909)
- 242313 Red Hat Update for tomcat (RHSA-2023:6570)
- 242462 Red Hat Update for tomcat (RHSA-2023:7065)
- 354924 Amazon Linux Security Advisory for tomcat7 : ALAS-2023-1738
- 356243 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-013
- 356298 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-008
- 356454 Amazon Linux Security Advisory for tomcat8 : ALAS-2023-1861
- 378459 IBM WebSphere Application Server Liberty Denial of Service (DoS) Vulnerability (6982047)
- 378460 IBM WebSphere Application Server Denial Of Service (DOS) Vulnerability (6982047)
- 378672 IBM MQ Denial of Service (DoS) Vulnerabilities (7007425)
- 6000246 Debian Security Update for tomcat9 (DSA 5522-1)
- 6000257 Debian Security Update for tomcat9 (DLA 3617-1)
- 672870 EulerOS Security Update for tomcat (EulerOS-SA-2023-1612)
- 673096 EulerOS Security Update for tomcat (EulerOS-SA-2023-2177)
- 691093 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (f68bb358-be8e-11ed-9215-00e081b7aa2d)
- 710733 Gentoo Linux Apache Tomcat Multiple Vulnerabilities (GLSA 202305-37)
- 730732 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-24998)
- 730733 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-24998)
- 730734 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-24998)
- 730753 Jenkins Multiple Security Vulnerabilities (SECURITY-3030, SECURITY-2120)
- 730810 Apache Tomcat denial of service Vulnerability (CVE-2023-24998)
- 730811 Apache Tomcat denial of service Vulnerability (CVE-2023-24998)
- 730812 Apache Tomcat denial of service Vulnerability (CVE-2023-24998)
- 730845 IBM MQ Appliance Denial-of Service Vulnerability (7007743)
- 730871 Atlassian Confluence Server and Data Center Third-Party Dependency Vulnerability (CONFSERVER-90185)
- 753764 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:0697-1)
- 753765 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:0696-1)
- 753773 SUSE Enterprise Linux Security Update for jakarta-commons-fileupload (SUSE-SU-2023:0730-1)
- 753805 SUSE Enterprise Linux Security Update for jakarta-commons-fileupload (SUSE-SU-2023:0758-1)
- 753891 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:1769-1)
- 754070 SUSE Enterprise Linux Security Update for apache-commons-fileupload (SUSE-SU-2023:2390-1)
- 754094 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:2505-1)
- 87542 Oracle WebLogic Server Multiple Vulnerabilities (CPUAPR2023)
- 941389 AlmaLinux Security Update for tomcat (ALSA-2023:6570)
- 941469 AlmaLinux Security Update for tomcat (ALSA-2023:7065)