CVE-2023-28709Patch(apache / 7-mode_transition_tool)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache 7-mode_transition_tool systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-193

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • 7-mode_transition_tool
  • debian_linux
  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
7-mode_transition_tooldebian_linuxtomcat

3 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 103-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • PulsePatch.io@pulsepatchio
    Patch

    `Apache Tomcat` has an incomplete fix (CVE-2023-28709) for a previous request smuggling vulnerability. Review your `Tomcat` deployments. #ApacheTomcat #Vulnerability #infosec https://www.pulsepatch.io/posts/cve-2023-28709-apache-tomcat-incomplete-fix

    Post summary

    Apache Tomcat has an incomplete fix for CVE-2023-28709, a request smuggling vulnerability; administrators are advised to review deployments to ensure proper mitigation.

    0000078
    1 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
OSdebiandebian_linux12.0--
Appnetapp7-mode_transition_tool---

Explore more