CVE-2023-28709

HIGH7.5EPSS 0.52%

tomcat10 - security update

Published: 7/6/2023Modified: 3/9/2026
Also known as:GHSA-cx6h-86xw-9x34DSA-5521-1BIT-tomcat-2023-28709DEBIAN-CVE-2023-28709DEBIAN-CVE-2023-41080DEBIAN-CVE-2023-42795DEBIAN-CVE-2023-45648

Description

The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (17)