Skip to content

CVE: 2023-28709 found in tomcat-embed-core - Version: 9.0.36 [JAVA] #160

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageJAVA
VulnerabilityDenial Of Service (DoS)
Vulnerability descriptionorg.apache.tomcat:tomcat-coyote is vulnerable to Denial Of Service (DoS). Bypassing the restriction on uploaded request parts may result in a Denial of Service if HTTP connector settings are different from the default. The Denial of Service may occur if a request query string exactly matches the maxParameterCount parameters.
CVE2023-28709
CVSS score7.1
Vulnerability present in version/s9.0.0.M1-9.0.73
Found library version/s9.0.36
Vulnerability fixed in version9.0.74
Library latest version11.0.9
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions