Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
4.6, 5.5, 6.0, 6.1, 6.2, 6.3
Description
We use Apache commons-fileupload 1.3.1. According to CVE-2016-3092 :
"The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string."
We should upgrade to 1.3.2.
Attachments
Attachments
Issue Links
- is a clone of
-
SOLR-9053 Upgrade fileupload-commons to 1.3.1
- Closed