Rewterz
Rewterz Threat Advisory – CVE-2023-25613 – Apache Kerby Vulnerability
February 21, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-25653 – Cisco node-jose Vulnerability
February 21, 2023

Rewterz Threat Advisory – CVE-2023-24998 – Apache Commons FileUpload and Tomcat Vulnerability

Severity

High

Analysis Summary

CVE-2023-24998

Apache Commons FileUpload and Tomcat are vulnerable to a denial of service, caused by not limit the number of request parts to be processed in the file upload function. By sending a specially-crafted request with series of uploads, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Impact

  • Denial of Service

Indicators Of Compromise

CVE

  • CVE-2023-24998

Affected Vendors

Apache

Affected Products

  • Apache Tomcat 10.1.0-M1
  • Apache Tomcat 10.1.4
  • Apache Commons FileUpload 1.0-beta-1
  • Apache Commons FileUpload 1.4

Remediation

Upgrade to the latest version of Apache Commons FileUpload, Apache Tomcat, available from the Apache Website.

Apache Website