QID 730734
Date Published: 2023-02-22
QID 730734: Apache Tomcat Denial of Service (DoS) Vulnerability (CVE-2023-24998)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
Apache Tomcat uses a packaged renamed copy of Apache Commons FileUpload to provide the file upload functionality defined in the Jakarta Servlet specification. Apache Tomcat was, therefore, also vulnerable to the Apache Commons FileUpload vulnerability CVE-2023-24998 as there was no limit to the number of request parts processed. This resulted in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Affected versions:
Apache Tomcat 10.1.0-M1 to 10.1.4
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to an invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation of this vulnerability could reveal sensitive information to an unauthorized attacker.
- Apache_Tomcat_10.1.5 -
tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.5
CVEs related to QID 730734
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|