GHSA-jm7m-8jh6-29hp

    Dashboard / Vulnerabilities / GHSA-jm7m-8jh6-29hp

    GHSA-jm7m-8jh6-29hp

    Published: 10 Oct 2023Last Modified: 13 Feb 2025

    Summary: Apache Tomcat Incomplete Cleanup vulnerability

    Details: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

    Affected packages

    Package

    Name: org.apache.tomcat:tomcat-coyote

    Purl: pkg:maven/org.apache.tomcat/tomcat-coyote

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 9.0.70
    Fixed -9.0.81

    Affected versions

    9.0.70
    9.0.71
    9.0.72
    9.0.73
    9.0.74
    9.0.75
    9.0.76
    9.0.78
    9.0.79
    9.0.80

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-jm7m-8jh6-29hp | CVE-DB