Apache Security Update – 23 May 2023

Apache has released a security update to address a vulnerability in Apache Tomcat.

The addressed vulnerability could allow the remote attacker to cause a denial of service by sending a specially crafted request using query string parameters.

Apache Tomcat Denial of Service Vulnerability (CVE-2023-28709):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

The affected versions:

  • Apache Tomcat “8.5.85 to 8.5.87”.
  • Apache Tomcat “9.0.71 to 9.0.73”.
  • Apache Tomcat “10.1.5 to 10.1.7”.
  • Apache Tomcat “11.0.0-M2 to 11.0.0-M4”.
Vulnerabilities

CVE-2023-28709

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache Security Advisory

References