Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ2bTMtY2Z2ai1neHFx

High severity vulnerability that affects commons-fileupload:commons-fileupload

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Permalink: https://github.com/advisories/GHSA-fvm3-cfvj-gxqq
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZ2bTMtY2Z2ai1neHFx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: 5 months ago


CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-fvm3-cfvj-gxqq, CVE-2016-3092
References: Blast Radius: 37.6

Affected Packages

maven:commons-fileupload:commons-fileupload
Dependent packages: 2,282
Dependent repositories: 103,825
Downloads:
Affected Version Ranges: < 1.3.2
Fixed in: 1.3.2
All affected versions: 1.2.1, 1.2.2, 1.3.1
All unaffected versions: 1.3.2, 1.3.3