{"schema_version":"1.9.0","id":"CVE-2023-24998","published":"2023-02-20T15:57:07.372Z","modified":"2026-08-12T03:51:40.576428066Z","aliases":["GHSA-hfrx-6qgj-fp6c"],"related":["ALSA-2023:6570","ALSA-2023:7065","SUSE-SU-2023:0695-1","SUSE-SU-2023:0696-1","SUSE-SU-2023:0697-1","SUSE-SU-2023:0730-1","SUSE-SU-2023:0758-1","SUSE-SU-2023:1769-1","SUSE-SU-2023:2390-1","SUSE-SU-2023:2505-1","SUSE-SU-2026:1058-1","openSUSE-SU-2024:12750-1","openSUSE-SU-2024:12950-1","openSUSE-SU-2024:13441-1"],"summary":"Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts","details":"Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.\n\n\n\n\nNote that, like all of the file upload limits, the\n          new configuration option (FileUploadBase#setFileCountMax) is not\n          enabled by default and must be explicitly configured.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/commons-fileupload","events":[{"introduced":"cdfbeaa120cba6a8f1527b91600317ee374450c2"},{"fixed":"1d9a750e5091b6e36aa81c2277200a4b2b5ecd8a"}],"database_specific":{"cpe":"cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0"},{"fixed":"1.5"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-24998.json"}}],"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/05/22/1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24998.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-24998"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-37"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230302-0013/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20241108-0002/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2023/dsa-5522"}],"database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/24xxx/CVE-2023-24998.json","unresolved_ranges":[{"extracted_events":[{"fixed":"1.5"},{"introduced":"11.0.0-M1"},{"last_affected":"11.0.0-M1"},{"introduced":"10.0.0-M1"},{"last_affected":"10.1.4"},{"introduced":"9.0.0-M1"},{"last_affected":"9.0.70"},{"introduced":"8.5.0"},{"last_affected":"8.5.84"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"1.5"}],"source":"DESCRIPTION"}]}}