Apache Commons FileUpload
cpe:2.3:a:apache:commons_fileupload:*:*:*:*:*:*:*
- >= 1.0, < 1.6
- >= 2.0.0-M1, < 2.0.0-M4
A denial-of-service vulnerability has been identified in Apache Commons FileUpload versions 1.0 prior to 1.6 and 2.0.0-M1 prior to 2.0.0-M4. The issue arises from the allocation of resources for multipart headers without adequate limits, allowing for potential resource exhaustion.
Exploitation of this vulnerability can lead to a denial-of-service condition, causing the application to become unresponsive or unavailable.
Users are advised to upgrade to Apache Commons FileUpload version 1.6 or 2.0.0-M4, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.