VDB
Sign up
HIGH

GHSA-vv7r-c36w-3prj

Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers

Quick fix

GHSA-vv7r-c36w-3prj — commons-fileupload:commons-fileupload: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.6.0</version> for commons-fileupload:commons-fileupload

Details

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.

This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4.

Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/commons-fileupload:commons-fileupload
Introduced in: 1.0Fixed in: 1.6.0
Fix# pom.xml: bump <version>1.6.0</version> for commons-fileupload:commons-fileupload
Maven/org.apache.commons:commons-fileupload2-core
Introduced in: 2.0.0-M1Fixed in: 2.0.0-M4
Fix# pom.xml: bump <version>2.0.0-M4</version> for org.apache.commons:commons-fileupload2-core

References