Apache Releases Security Updates
Apache releases security updates addressing a denial-of-service vulnerability in Apache Tomcat and Commons FileUpload
Summary
Apache releases security updates addressing a denial-of-service vulnerability in Apache Tomcat and Commons FileUpload
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Apache Software Foundation has released security updates to address a denial-of-service (DoS) vulnerability in Apache Tomcat and Commons FileUpload. The vulnerability CVE-2023-24998, could allow a remote attacker to initiate a series of uploads that could lead to DoS condition.
Remediation advice
Affected organisations are encouraged to review the appropriate Apache security advisory below and apply the relevant updates.
Remediation steps
| Type | Step |
|---|---|
| Guidance |
Apache Tomcat denial-of-service CVE-2023-24998 https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M3 |
| Guidance |
Apache Tomcat denial-of-service CVE-2023-24998 https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.5 |
| Guidance |
Apache Tomcat denial-of-service CVE-2023-24998 https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.71 |
| Guidance |
Apache Tomcat denial-of-service CVE-2023-24998 https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.85 |
| Guidance |
Apache Commons FileUpload denial-of-service CVE-2023-24998 https://commons.apache.org/proper/commons-fileupload/security-reports.html |
Definitive source of threat updates
Last edited: 22 February 2023 2:01 pm