Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Upstream security page: https://commons.apache.org/proper/commons-fileupload/security-reports.html#Fixed_in_Apache_Commons_FileUpload_1.5 Upstream commit: https://github.com/apache/commons-fileupload/commit/e20c04990f7420ca917e96a84cec58b13a1b3d17
Created apache-commons-fileupload tracking bugs for this issue: Affects: epel-7 [bug 2173752] Affects: fedora-all [bug 2173753]
Created tomcat tracking bugs for this issue: Affects: fedora-all [bug 2173782]
This issue has been addressed in the following products: RHINT Camel-Springboot 3.20.1 Via RHSA-2023:2100 https://access.redhat.com/errata/RHSA-2023:2100
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-24998
This issue has been addressed in the following products: OpenShift Developer Tools and Services for OCP 4.13 Via RHSA-2023:3299 https://access.redhat.com/errata/RHSA-2023:3299
Created tomcat tracking bugs for this issue: Affects: epel-8 [bug 2211066]
This issue has been addressed in the following products: Red Hat JBoss Web Server 5.7 on RHEL 7 Red Hat JBoss Web Server 5.7 on RHEL 8 Red Hat JBoss Web Server 5.7 on RHEL 9 Via RHSA-2023:4909 https://access.redhat.com/errata/RHSA-2023:4909
This issue has been addressed in the following products: JWS 5.7.4 release Via RHSA-2023:4910 https://access.redhat.com/errata/RHSA-2023:4910
This bug has not been fixed in the Tomcat 9.0.62 for RHEL 8 and RHEL 9 (NOTE: _NOT_ the JBoss Tomcat, the one available to anyone running plain old RHEL 8 or 9).
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:6570 https://access.redhat.com/errata/RHSA-2023:6570
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:7065 https://access.redhat.com/errata/RHSA-2023:7065