Apache Software Foundation Commons FileUpload 1.4

CPE Details

Apache Software Foundation Commons FileUpload 1.4
1.4
2023-02-28
11h10 +00:00
2023-04-18
10h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:commons_fileupload:1.4:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

commons_fileupload

Version

1.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-48976 2025-06-16 15h00 +00:00 Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
7.5
High
CVE-2023-24998 2023-02-20 15h57 +00:00 Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
7.5
High