Tomcat 8.5.x/9.0.x Commons FileUpload Incomplete Stream Deletion DoS
CVE-2023-42794 Published on October 10, 2023

Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Vendor Advisory NVD

Weakness Type

What is an Insufficient Cleanup Vulnerability?

The software does not properly "clean up" and remove temporary or supporting resources after they have been used.

CVE-2023-42794 has been classified to as an Insufficient Cleanup vulnerability or weakness.


Products Associated with CVE-2023-42794

Want to know whenever a new CVE is published for Apache Tomcat? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache Tomcat:

Exploit Probability

EPSS
0.32%
Percentile
54.38%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.