{"schema_version":"1.7.5","id":"GHSA-cx6h-86xw-9x34","published":"2023-07-06T21:14:59Z","modified":"2026-03-24T11:11:51.396429Z","aliases":["BIT-tomcat-2023-28709","CVE-2023-28709"],"summary":"Apache Tomcat - Fix for CVE-2023-24998 was incomplete","details":"The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.","affected":[{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M2"},{"fixed":"11.0.0-M5"}]}],"versions":["11.0.0-M3","11.0.0-M4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-cx6h-86xw-9x34/GHSA-cx6h-86xw-9x34.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.5"},{"fixed":"10.1.8"}]}],"versions":["10.1.5","10.1.6","10.1.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-cx6h-86xw-9x34/GHSA-cx6h-86xw-9x34.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.71"},{"fixed":"9.0.74"}]}],"versions":["9.0.71","9.0.72","9.0.73"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-cx6h-86xw-9x34/GHSA-cx6h-86xw-9x34.json"}},{"package":{"name":"org.apache.tomcat:tomcat-coyote","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.5.85"},{"fixed":"8.5.88"}]}],"versions":["8.5.85","8.5.86","8.5.87"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-cx6h-86xw-9x34/GHSA-cx6h-86xw-9x34.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28709"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/5badf94e79e5de206fc0ef3054fd536b1bb787cd"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/ba848da71c523d94950d3c53c19ea155189df9dc"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/d53d8e7f77042cc32a3b98f589496a1ef5088e38"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/fbd81421629afe8b8a3922d59020cde81caea861"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://lists.apache.org/thread/7wvxonzwb7k9hx9jt3q33cmy7j97jo3j"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-37"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230616-0004"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html"},{"type":"WEB","url":"https://www.debian.org/security/2023/dsa-5521"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/05/22/1"}],"database_specific":{"cwe_ids":["CWE-193"],"github_reviewed":true,"github_reviewed_at":"2023-07-06T23:34:50Z","nvd_published_at":"2023-05-22T11:15:09Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}