Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Apache Tomcat  CVE score Critical and High


dateCVEdescriptionversionsRisk for Delft-FEWSJIRAupgrade strategy
May 2023CVE-2022-28079The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector

settings were used such that the maxParameterCount could be reached

using query string parameters and a request was submitted that supplied

exactly maxParameterCount parameters in the query string, the limit for

uploaded request parts could be bypassed with the potential for a denial

of service to occur.

Upgrade to latest version of Apache Tomcat.

Note: Delft-FEWS releases < 2023.01 require Apache Tomcat 9, release >= 2023.01 require Apache Tomcat 10.