Bug 2210321 (CVE-2023-28709)

Summary: CVE-2023-28709 tomcat: Fix for CVE-2023-24998 was incomplete
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: csutherl, huwang, jclere, kyoshida, mmadzin, peholase, pjindal, rhcs-maint, szappis
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Apache Tomcat 11.0.0-M5, Apache Tomcat 10.1.8, Apache Tomcat 9.0.74, Apache Tomcat 8.5.88 Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in Apache Tomcat due to an incomplete fix for CVE-2023-24998, which aims to limit the uploaded request parts that can be bypassed in a request. This issue may allow an attacker to use a malicious upload or series of uploads to trigger a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2210322, 2210629, 2210630, 2210631, 2210632, 2210323, 2210627, 2210628    
Bug Blocks: 2209054    

Description Patrick Del Bello 2023-05-26 15:18:22 UTC
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was       submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

https://lists.apache.org/thread/7wvxonzwb7k9hx9jt3q33cmy7j97jo3j
http://www.openwall.com/lists/oss-security/2023/05/22/1

Comment 1 Patrick Del Bello 2023-05-26 15:21:09 UTC
Created tomcat tracking bugs for this issue:

Affects: epel-all [bug 2210323]
Affects: fedora-all [bug 2210322]