CVE-2023-28709 is an incomplete fix for CVE-2023-24998 affecting Apache Tomcat versions 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73, and 8.5.85 to 8.5.87, as well as related Debian and NetApp products. This vulnerability allows for a denial of service if specific non-default HTTP connector settings are used and a request with exactly maxParameterCount query string parameters is submitted, bypassing the limit for uploaded request parts. With a CVSS score of 7.5 (HIGH), it has a low attack complexity and requires no privileges or user interaction, posing a significant availability risk. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, but it has garnered moderate community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5.85, <= 8.5.87CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 9.0.71, <= 9.0.73CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
>= 10.1.5, <= 10.1.7CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* | ||
11.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:* | ||
11.0.0CPE matchmatch criteria | cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.