CVE-2023-24998
tomcat9 - security update
7.5
HIGH
CVSS 3.1
EPSS 46.8%
描述
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
如何修補 CVE-2023-24998
要修補 CVE-2023-24998,請將受影響套件升級到下列已修補版本。
- —升級至 1.4-1+deb11u1 或更新版本
- —升級至 1.4-1+deb11u1 或更新版本
- —升級至 10.1.5-1 或更新版本
- —升級至 9.0.43-2~deb11u7 或更新版本
- —升級至 9.0.31-1~deb10u9 或更新版本
- —升級至 9.0.43-2~deb11u7 或更新版本
- —升級至 1.5 或更新版本
- —升級至 10.1.5 或更新版本
- —升級至 10.1.5 或更新版本
- —升級至 10.1.5 或更新版本
CVE-2023-24998 正在被利用嗎?
中等 — EPSS 為 46.8%,可持續追蹤但非最高優先。
受影響套件(10)
- from 0, < 1.4-1+deb11u1
- from 0, < 1.4-1+deb11u1
- from 0, < 10.1.5-1
- from 0, < 9.0.43-2~deb11u7
- from 0, < 9.0.31-1~deb10u9
- from 0, < 9.0.43-2~deb11u7
- from 0, < 1.5
- >= 10.1.0-M1, < 10.1.5
- >= 10.1.0-M1, < 10.1.5
- >= 10.1.0-M1, < 10.1.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |