CVE-2023-42794 - CVE House
Back to Database
Status published Unknown CVE-2023-42794

Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows

Vulnerability Description

Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Other, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-42794

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mohammad Khedmatgozar (cellbox)

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Tomcat
Vulnerable Versions:
9.0.70, 8.5.85, 10.0.0-M1

Timeline

Official Publish: October 10th, 2023
Last Modified: October 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.