Tracker / CVE-2023-24998
CVE-2023-24998
High 7.5
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
Affected products and versions
| apache | commons_fileupload |
|---|---|
| apache | commons_fileupload · 1.0 → 1.5 |
| debian | debian_linux |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.