CVE-2023-24998
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 48.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 48.79% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- apache/commons fileupload · debian/debian linux
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/05/22/1Mailing List
- https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoyMailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.htmlThird Party Advisory
- https://security.gentoo.org/glsa/202305-37Third Party Advisory
- https://www.debian.org/security/2023/dsa-5522Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/05/22/1Mailing List
- https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoyMailing List, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00020.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html
- https://security.gentoo.org/glsa/202305-37Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230302-0013/
- https://security.netapp.com/advisory/ntap-20241108-0002/
- https://www.debian.org/security/2023/dsa-5522Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.