CVE-2023-24998

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/02/2023
Last modified:
03/11/2025

Description

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.<br /> <br /> <br /> <br /> <br /> Note that, like all of the file upload limits, the<br /> new configuration option (FileUploadBase#setFileCountMax) is not<br /> enabled by default and must be explicitly configured.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:* 1.0 (including) 1.5 (excluding)
cpe:2.3:a:apache:commons_fileupload:1.0:beta:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*