PT-2023-4888 · Atlassian+6 · Confluence Data Center/Server+9

Chenfeng Nie

+2

·

Published

2023-04-19

·

Updated

2026-03-26

·

CVE-2023-28709

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M2 through 11.0.0-M4 Apache Tomcat versions 10.1.5 through 10.1.7 Apache Tomcat versions 9.0.71 through 9.0.73 Apache Tomcat versions 8.5.85 through 8.5.87 Bamboo Data Center and Server version 8.1.12 and later, prior to 9.2.4 and 9.3.1 Confluence Data Center & Server versions 7.13.15 through 7.13.18 Confluence Data Center & Server versions 7.19.7 through 7.19.10 Confluence Data Center & Server versions 8.1.1 through 8.4.0
Description The issue is related to an incomplete fix for a vulnerability in Apache Tomcat, which can be exploited to bypass the limit for uploaded request parts, potentially leading to a denial of service. This can occur when non-default HTTP connector settings are used, allowing an attacker to reach the maxParameterCount using query string parameters. If a request is submitted with exactly maxParameterCount parameters in the query string, the limit for uploaded request parts can be bypassed.
Recommendations For Apache Tomcat versions 11.0.0-M2 through 11.0.0-M4, upgrade to a version later than 11.0.0-M4. For Apache Tomcat versions 10.1.5 through 10.1.7, upgrade to a version later than 10.1.7. For Apache Tomcat versions 9.0.71 through 9.0.73, upgrade to a version later than 9.0.73. For Apache Tomcat versions 8.5.85 through 8.5.87, upgrade to a version later than 8.5.87. For Bamboo Data Center and Server, upgrade to version 9.2.4 or 9.3.1, or later. For Confluence Data Center & Server, upgrade to version 7.13.19, 7.19.11, or 8.4.1, or later. As a temporary workaround, consider restricting access to the vulnerable maxParameterCount parameter in the HTTP connector settings until a patch is available.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6570
ALSA-2023:7065
ALT-PU-2024-4687
ALT-PU-2024-4975
ALT-PU-2025-9146
BDU:2023-05380
BIT-TOMCAT-2023-28709
CESA-2023_7065
CVE-2023-28709
DSA-5521-1
GHSA-CX6H-86XW-9X34
MGASA-2023-0191
OESA-2024-1100
OPENSUSE-SU-2024:12953-1
OPENSUSE-SU-2024:13441-1
RHSA-2023:4909
RHSA-2023:6570
RHSA-2023:7065
RHSA-2023_6570
RHSA-2023_7065
ROSA-SA-2024-2418
SUSE-SU-2023:2318-1
SUSE-SU-2023:2319-1
SUSE-SU-2023:2504-1
SUSE-SU-2023:2505-1
SUSE-SU-2026:1058-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Bamboo
Bamboo Data Center/Server
Centos
Confluence
Confluence Data Center/Server
Red Hat
Suse