VYPR
Medium severity5.3NVD Advisory· Published Feb 1, 2023· Updated Jun 17, 2026

CVE-2022-37034

CVE-2022-37034

Description

In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.

Affected products

4
  • Dotcms/Dotcms4 versions
    cpe:2.3:a:dotcms:dotcms:*:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:a:dotcms:dotcms:*:*:*:*:-:*:*:*range: >=5.2.0,<22.10
    • cpe:2.3:a:dotcms:dotcms:*:*:*:*:lts:*:*:*range: <21.06.12
    • (no CPE)
    • (no CPE)range: 5.x-22.06

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.