Korean
<< Back
VID 210248
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The version of Tomcat installed on the remote host is prior to 10.1.8. It is, therefore, affected by a vulnerability as referenced in the fixed_in_apache_tomcat_10.1.8_security-10.

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87.
If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

* References:
https://github.com/apache/tomcat/commit/ba848da71c523d94950d3c53c19ea155189df9dc
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.8

* Platforms Affected:
Apache Tomcat Server versions 10.1.x prior to 10.1.8
Any operating system Any version
Recommendation Upgrade to the latest version of Apache Tomcat Server (10.1.8 or later), available from the Apache Software Foundation download site, http://tomcat.apache.org/
Related URL CVE-2023-28709 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)