Description
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.
Related CPE's
a
dotcms
dotcms
3
References
https://www.dotcms.com/security/SI-65
Vendor Advisory
https://www.dotcms.com/security/SI-65
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2023-02-01T22:15:09.337Z
3 years agoLast modified
2025-03-27T16:15:37.643Z
11 months ago