/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-h36m-pmcw-97jx

Published

Last updated

https://images.chainguard.dev/security/CGA-h36m-pmcw-97jx
Package

tomcat-8.5.87

Repository

Chainguard

Latest Update
Fix not planned
Aliases
  • CVE-2023-28709
  • GHSA-cx6h-86xw-9x34

Severity

Unknown

Summary

Apache Tomcat - Fix for CVE-2023-24998 was incomplete

Description

The fix for CVE-2023-24998 was incomplete. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs