Red Hat and Apache addressed CVE-2014-0050, a denial-of-service flaw in Apache Commons FileUpload and its bundled copies in Apache Tomcat. An unauthenticated attacker could send a multipart request with a malformed or oversized Content-Type header, causing MultipartStream to enter an infinite loop and exhaust service availability. Affected upstream releases included Commons FileUpload 1.0–1.3, Tomcat 7.0.0–7.0.50, and Tomcat 8.0.0-RC1–8.0.1.
Red Hat issued Moderate-severity updates for JBoss EAP 6.2.1/JBoss Web and incorporated the fix into JBoss A-MQ 6.1.0, alongside other security corrections. Organizations should install the relevant vendor updates, reconcile any locally modified configurations, and restart JBoss services; where patching cannot occur immediately, limiting Content-Type headers to fewer than 4,091 bytes reduces exposure. Upstream remediation includes Commons FileUpload 1.3.1, Tomcat 7.0.51, or Tomcat 8.0.2 and later.

See affected versions and whether adversaries are exploiting it.
13 events from the most recent confirmed update back to the earliest known activity.
Red Hat released a Moderate-severity JBoss EAP update for Red Hat Enterprise Linux 5 and 6, including fixed jbossweb packages for CVE-2014-0050. Red Hat instructed customers to update and restart the JBoss server process.
Red Hat issued a Moderate-impact update for JBoss Enterprise Application Platform 6.2.1 that fixed CVE-2014-0050 in the embedded Apache Commons FileUpload component. The flaw allowed a remote multipart request with a malformed Content-Type header to make JBoss Web loop indefinitely.
Mark Thomas published an advisory describing CVE-2014-0050, which affects Commons FileUpload 1.0 through 1.3 and bundled copies in Tomcat 7 and 8. Apache recommended upgrades, patches, or limiting Content-Type headers to fewer than 4,091 bytes as mitigation.
Red Hat addressed CVE-2014-0050 for JBoss Portal 6.2.0 through RHSA-2015:1009.
Red Hat addressed CVE-2014-0050 for JBoss Enterprise Web Server 2.0.1 through RHSA-2014:0527 and RHSA-2014:0528, and for JBoss Enterprise Web Server 2 on RHEL 5 and 6 through RHSA-2014:0525 and RHSA-2014:0526.
Red Hat addressed CVE-2014-0050 in Red Hat JBoss Operations Network 3.2.1 through RHSA-2014:0473.
Red Hat addressed CVE-2014-0050 for Red Hat JBoss Fuse Service Works 6.0.0 through RHSA-2014:0459.
Red Hat addressed CVE-2014-0050 in Fuse ESB Enterprise/MQ Enterprise 7.1.0 R1 P3 through RHSA-2014:0452.
Red Hat addressed CVE-2014-0050 for Red Hat Enterprise Linux 6 through RHSA-2014:0429.
Red Hat released the Moderate-impact JBoss A-MQ 6.1.0 update for A-MQ 6.0.0, fixing CVE-2014-0050 and eight other security vulnerabilities. The update also addressed flaws in Hadoop RPC, Spring Framework, HawtJNI, and ZooKeeper.
Red Hat addressed CVE-2014-0050 in Red Hat JBoss Fuse 6.1.0 through RHSA-2014:0400.
Red Hat addressed CVE-2014-0050 for JBoss BRMS 6.0.1 and JBoss BPM Suite 6.0.1 through RHSA-2014:0373.
Apache corrected the Apache Commons FileUpload flaw in source commit r1565143 and the related Tomcat 7 issue in commit r1565169. The flaw could cause an infinite loop when processing a crafted multipart Content-Type header.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcerhn.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceseclists.org
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.