cbcvebase.
CVE-2023-42794
published 2023-10-10

CVE-2023-42794: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through…

PriorityP429medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
1.85%
77.0th percentile
Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 8.5.85 < 8.5.948.5.94
apachetomcat>= 9.0.70 < 9.0.819.0.81
apache_software_foundationapache_tomcat8.5.85 – 8.5.93
apache_software_foundationapache_tomcat9.0.70 – 9.0.80
atlassianconfluence_data_center
debiantomcat10
debiantomcat9

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_apache5.9MEDIUM
vendor_debian5.9LOW
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.