Announcement

Collapse
No announcement yet.
X
  • Filter
  • Time
Clear All
new posts

    CVE-2025-48976

    Hello

    Our scans are reporting security vulnerability (CVE-2025-48976 ) in a commons-fileupload2-core-2.0.0-M1.jar which is part of smartclient.
    Could you please share if smartclient is vulnerable ?

    Thanks

    #2
    That's a DOS - an attacker can put together an upload that causes the server to allocate lots of memory without the attacker having to send very much data.

    You are only vulnerable if you allow multipart file uploads from untrusted users.

    If that's a concern, the fixed library is backwards compatible.

    Comment


      #3
      Thanks for sharing.

      Comment

      Working...
      X