CVE-2023-28709: Apache Tomcat: Fix for CVE-2023-24998 is incomplete
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
Other sources
The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.6-1+deb12u1Fixed in 10.1.16-1 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.31-1~deb10u6Fixed in 9.0.31-1~deb10u10Fixed in 9.0.43-2~deb11u6Fixed in 9.0.43-2~deb11u9Fixed in 9.0.70-2 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 8.5.88 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.74 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 10.1.8 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 11.0.0-M5 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.8 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.74 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.88 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.117.1.3
Event History
Frequently Asked Questions
What is CVE-2023-28709?
CVE-2023-28709 is a vulnerability in Apache Tomcat that allows for a denial of service attack.
Which versions of Apache Tomcat are affected by CVE-2023-28709?
Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73, and 8.5.85 to 8.5.87 are affected by CVE-2023-28709.
How severe is CVE-2023-28709?
CVE-2023-28709 has a severity rating of 7.5 (high).
Is there a fix available for CVE-2023-28709?
Yes, the fix for CVE-2023-28709 is available in Apache Tomcat versions 8.5.88, 9.0.74, 10.1.8, and 11.0.0-M5.
Where can I find more information about CVE-2023-28709?
You can find more information about CVE-2023-28709 on the Red Hat Security Advisory page and the Apache Tomcat mailing list.