Lucene search

K
atlassianRichatkinsATLASSIAN:CONFSERVER-32557
HistoryFeb 10, 2014 - 5:56 a.m.

Security vulnerability in apache commons fileupload

2014-02-1005:56:15
richatkins
jira.atlassian.com
43

EPSS

0.191

Percentile

96.3%

Apache commons-fileupload 1.3.1 was released this weekend with a fix for CVE-2014-0050, involving a DoS attack when using specially crafted multipart requests. We need to determine if Confluence is vulnerable, and if so, upgrade to this version of the library.