Skip to main content

Apache Releases Security Updates

Apache releases security updates addressing a denial-of-service vulnerability in Apache Tomcat and Commons FileUpload

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Apache releases security updates addressing a denial-of-service vulnerability in Apache Tomcat and Commons FileUpload


Threat details

Introduction

The Apache Software Foundation has released security updates to address a denial-of-service (DoS) vulnerability in Apache Tomcat and Commons FileUpload. The vulnerability CVE-2023-24998, could allow a remote attacker to initiate a series of uploads that could lead to DoS condition. 


Remediation advice

Affected organisations are encouraged to review the appropriate Apache security advisory below and apply the relevant updates.


Remediation steps

Type Step
Guidance

Apache Tomcat denial-of-service CVE-2023-24998
Apache Tomcat 11.0.0-M1 should update to Apache Tomcat 11.0.0-M3 or later


https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M3
Guidance

Apache Tomcat denial-of-service CVE-2023-24998
Apache Tomcat 10.1.0-M1 to 10.1.4 should update to Apache Tomcat 10.1.5 or later


https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.5
Guidance

Apache Tomcat denial-of-service CVE-2023-24998
Apache Tomcat 9.0.0-M1 to 9.0.70 should update to Apache Tomcat 9.0.71 or later


https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.71
Guidance

Apache Tomcat denial-of-service CVE-2023-24998
Apache Tomcat 8.5.0 to 8.5.84 should update to Apache Tomcat 8.5.85 or later


https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.85
Guidance

Apache Commons FileUpload denial-of-service CVE-2023-24998
Apache Commons FileUpload 1.0? - 1.4 should update Apache Commons FileUpload 1.5


https://commons.apache.org/proper/commons-fileupload/security-reports.html


Last edited: 22 February 2023 2:01 pm