Apache Security Updates 21 February 2023

Apache has released security updates to address vulnerabilities in multiple products.

The addressed vulnerabilities could allow the remote attacker to manipulate data or cause a denial of service attack on the vulnerable system.

Sample of the addressed vulnerabilities:

Apache Commons FileUpload and Tomcat Denial of Service (CVE-2023-24998):

• CVSS: 7.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: None

• User Interaction: None

• Consequences: Denial of Service

Affected products:

• Apache Commons.

• Apache Tomcat.

• Apache Kerby.

Vulnerabilities
  • CVE-2023-24998
  • CVE-2023-25613
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache Commons Security Advisory

Apache Tomcat Security Advisory

Apache Kerby Security Advisory

References