Incomplete Cleanup vulnerability in Apache Tomcat.
The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full.
Other, EOL versions may also be affected.
Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcat-el-3.0-apiUpgrade tomcat-libUpgrade tomcatUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-4.0-api | Jan 18, 2024 | Oct 10, 2023 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.94Upgrade Apache Tomcat to 9.0.81 | Oct 11, 2023 | Oct 10, 2023 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Nov 21, 2023 |
| Centos_linux | — | Upgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-webappsUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-api | Jan 11, 2024 | Oct 10, 2023 |
| Oracle_linux | — | Upgrade tomcat-jsp-2.3-apiUpgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-api | Jan 11, 2024 | Oct 10, 2023 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Oct 10, 2023 |
| Redhat_linux | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-lib | Jan 11, 2024 | Oct 10, 2023 |
| Suse | — | Upgrade tomcat-admin-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-libUpgrade tomcat-embedUpgrade tomcat-el-3_0-apiUpgrade tomcat-docs-webappUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-jsvcUpgrade tomcat-javadocUpgrade tomcat-webappsUpgrade tomcat | Feb 15, 2024 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub