Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-0050

Severity
7.5HIGH
EPSS
92.7%
top 0.25%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 1
Latest updateDec 21

Description

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages6 packages

Mavenorg.apache.tomcat:tomcat8.0.0-RC18.0.3+1
Debianlibcommons-fileupload-java< 1.3.1-1+3
NVDapache/tomcat53 versions+52

Patches

🔴Vulnerability Details

4
GHSA
Commons FileUpload Denial of service vulnerability2018-12-21
OSV
Commons FileUpload Denial of service vulnerability2018-12-21
OSV
CVE-2014-0050: MultipartStream2014-04-01
CVEList
CVE-2014-0050: MultipartStream2014-03-28

💥Exploits & PoCs

1
Exploit-DB
Apache Commons FileUpload and Apache Tomcat - Denial of Service2014-02-12

🔍Detection Rules

1
Suricata
ET WEB_SERVER Apache Tomcat Boundary Overflow DOS/File Upload Attempt2014-02-12

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2014-03-06
Red Hat
apache-commons-fileupload: denial of service due to too-small buffer size used by MultipartStream2014-02-06
Debian
CVE-2014-0050: libcommons-fileupload-java - MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apach...2014
Apache
Apache tomcat: CVE-2014-0050

💬Community

4
Bugzilla
Upgrade apache-commons-fileupload to 1.3.1 to address CVE-2014-00502014-03-19
Bugzilla
CVE-2014-0050 apache-commons-fileupload: denial of service due to too-small buffer size used bt MultipartStream [fedora-all]2014-02-13
Bugzilla
CVE-2014-0050 tomcat: apache-commons-fileupload: denial of service due to too-small buffer size used bt MultipartStream [fedora-all]2014-02-13
Bugzilla
CVE-2014-0050 apache-commons-fileupload: denial of service due to too-small buffer size used by MultipartStream2014-02-06