commons-fileupload:commons-fileupload
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting commons-fileupload:commons-fileuploadpage 1 of 1
- CVE-2013-0248NONECVSS 0.0✓ Fixed in 1.2.22013-03-15
vulnerable: 1.0, 1.1, 1.1.1, 1.2, 1.2.1
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
- CVE-2013-2186NONECVSS 0.0✓ Fixed in 1.3.12013-10-28
vulnerable: 1.0 ... 1.3 (9 versions)
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a …
- CVE-2014-0050NONECVSS 0.0✓ Fixed in 1.3.12014-04-01
vulnerable: 1.0 ... 1.3 (9 versions)
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type he…
- CVE-2016-1000031CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.3.32016-10-25
vulnerable: 1.0 ... 1.3.2 (13 versions)
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
- CVE-2016-3092HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.22016-07-04
vulnerable: 1.0 ... 1.3.1-jenkins-2 (12 versions)
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial o…
- CVE-2023-24998HIGHCVSS 7.5EG 7.5✓ Fixed in 1.52023-02-20
vulnerable: 1.0 ... 1.4 (15 versions)
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file …
Check whether commons-fileupload:commons-fileupload is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for commons-fileupload:commons-fileupload CVEs against the assets you own.
Start Free Scan →