CVE-2023-24998
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
- Affected products
- Alt Linux, Almalinux, Apache Commons Fileupload, Apache Tomcat, Astra Linux, Centos, Debian, Red Hat
- Apache Commons Fileupload
- < 1.5, 1.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 46.8% (99th percentile)
- Weakness
- CWE-770
- NVD status
- Modified
- Published
- 2023-02-20
CVE-2023-24998 at NVD
1 known exploit for CVE-2023-24998
Proof-of-concept code and exploit modules indexed by Sploitus