'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2014-0050: Apache Commons FileUpload Denial of Service
Severity:high
CVE ID:CVE-2014-0050
| Descripiton:
|
Apache HTTP Server, colloquially called Apache, is the world's most used Web server software. Apache is develop and maintained by an open coummunity of developers under the auspices of the Apache Software Foundation. MultipartStream.java in Apache Common FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service via a crafted Content-Type header that bypasses a loop's intended exit conditions. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.