CVE-2023-42794

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/10/2023
Last modified:
13/02/2025

Description

Incomplete Cleanup vulnerability in Apache Tomcat.<br /> <br /> The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, <br /> in progress refactoring that exposed a potential denial of service on <br /> Windows if a web application opened a stream for an uploaded file but <br /> failed to close the stream. The file would never be deleted from disk <br /> creating the possibility of an eventual denial of service due to the <br /> disk being full.<br /> <br /> Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 8.5.85 (including) 8.5.94 (excluding)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 9.0.70 (including) 9.0.81 (excluding)