Lucene search

K
amazonAmazonALAS-2023-1861
HistoryOct 12, 2023 - 3:48 p.m.

Important: tomcat8

2023-10-1215:48:00
alas.aws.amazon.com
11
fileupload
dos
open redirect
apache tomcat8

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.034 Low

EPSS

Percentile

91.4%

Issue Overview:

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured. (CVE-2023-24998)

URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.

The vulnerability is limited to the ROOT (default) web application. (CVE-2023-41080)

Affected Packages:

tomcat8

Issue Correction:
Run yum update tomcat8 to update your system.

New Packages:

noarch:  
    tomcat8-admin-webapps-8.5.93-1.94.amzn1.noarch  
    tomcat8-log4j-8.5.93-1.94.amzn1.noarch  
    tomcat8-lib-8.5.93-1.94.amzn1.noarch  
    tomcat8-docs-webapp-8.5.93-1.94.amzn1.noarch  
    tomcat8-8.5.93-1.94.amzn1.noarch  
    tomcat8-javadoc-8.5.93-1.94.amzn1.noarch  
    tomcat8-webapps-8.5.93-1.94.amzn1.noarch  
    tomcat8-jsp-2.3-api-8.5.93-1.94.amzn1.noarch  
    tomcat8-servlet-3.1-api-8.5.93-1.94.amzn1.noarch  
    tomcat8-el-3.0-api-8.5.93-1.94.amzn1.noarch  
  
src:  
    tomcat8-8.5.93-1.94.amzn1.src  

Additional References

Red Hat: CVE-2023-24998, CVE-2023-41080

Mitre: CVE-2023-24998, CVE-2023-41080

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.034 Low

EPSS

Percentile

91.4%