CVE-2023-42794
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2023
Last modified:
13/02/2025
Description
Incomplete Cleanup vulnerability in Apache Tomcat.<br />
<br />
The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, <br />
in progress refactoring that exposed a potential denial of service on <br />
Windows if a web application opened a stream for an uploaded file but <br />
failed to close the stream. The file would never be deleted from disk <br />
creating the possibility of an eventual denial of service due to the <br />
disk being full.<br />
<br />
Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | 8.5.85 (including) | 8.5.94 (excluding) |
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | 9.0.70 (including) | 9.0.81 (excluding) |
To consult the complete list of CPE names with products and versions, see this page