CVE-2023-28709
Summary
| CVE | CVE-2023-28709 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-22 11:15:00 UTC |
| Updated | 2023-10-11 07:15:00 UTC |
| Description | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2023-28709 Apache Tomcat Vulnerability in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| oss-security - CVE-2023-28709 Apache Tomcat - Fix for CVE-2023-24998 was
incomplete |
MISC |
www.openwall.com |
|
| Apache Tomcat: Multiple Vulnerabilities (GLSA 202305-37) — Gentoo security |
MISC |
security.gentoo.org |
|
| lists.apache.org/thread/7wvxonzwb7k9hx9jt3q33cmy7j97jo3j |
MISC |
lists.apache.org |
|
| Debian -- Security Information -- DSA-5521-1 tomcat10 |
MISC |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150688 Apache Tomcat Denial Of Service (DoS) Vulnerability (CVE-2023-28709)
- 161103 Oracle Enterprise Linux Security Update for tomcat (ELSA-2023-6570)
- 161166 Oracle Enterprise Linux Security Update for tomcat (ELSA-2023-7065)
- 20354 Oracle Database 19c Critical Patch Update - July 2023
- 20355 Oracle Database 21c Critical Patch Update - July 2023
- 20356 Oracle Database 19c Critical OJVM Patch Update - July 2023
- 242102 Red Hat Update for red hat jboss web server 5.7.4 (RHSA-2023:4909)
- 242313 Red Hat Update for tomcat (RHSA-2023:6570)
- 242462 Red Hat Update for tomcat (RHSA-2023:7065)
- 296101 Oracle Solaris 11.4 Support Repository Update (SRU) 59.138.2 Missing (CPUJUL2023)
- 355571 Amazon Linux Security Advisory for tomcat8 : ALAS-2023-1779
- 355643 Amazon Linux Security Advisory for tomcat9 : ALAS2023-2023-238
- 356182 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-001
- 356270 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-001
- 356477 Amazon Linux Security Advisory for tomcat : ALAS2TOMCAT8.5-2023-001
- 356508 Amazon Linux Security Advisory for tomcat : ALAS2TOMCAT9-2023-001
- 6000247 Debian Security Update for tomcat10 (DSA 5521-1)
- 710733 Gentoo Linux Apache Tomcat Multiple Vulnerabilities (GLSA 202305-37)
- 730810 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-28709)
- 730811 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-28709)
- 730812 Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-28709)
- 730871 Atlassian Confluence Server and Data Center Third-Party Dependency Vulnerability (CONFSERVER-90185)
- 731322 Atlassian Bamboo Server and Data Center Information Exposure Vulnerability (BAM-22479, BAM-22601)
- 754057 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:2318-1)
- 754094 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:2505-1)
- 754095 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:2504-1)
- 941389 AlmaLinux Security Update for tomcat (ALSA-2023:6570)
- 941469 AlmaLinux Security Update for tomcat (ALSA-2023:7065)