Overview
About vulnerability
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
Details
- Affected product:
- AlmaLinux 9.2 ESU , Apache Commons , Apache Struts , Apache Tapestry , Apache Tomcat , Spring , Ubuntu 18.04 ELS , cocoon , lucene , myfaces , solr
- Affected packages:
- cocoon-core-modules @ 2.3.0 (+532 more)
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.