StackRadar

CVE-2023-42794

Medium

Advisory

Published 10 Oct 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.019
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2
of 17,781 indexed, latest versions
Container images
2
deployed by those charts
Fix available
3 of 3
affected packages

Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows

Carried by container images the latest versions of 2 of 17,781 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
tomcat-coyotemaven9.0.73, 9.0.809.0.812
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
OSV records
BIT-tomcat-2023-42794GHSA-jm7m-8jh6-29hp

Charts affected

2 by stars
ChartLatestAffected imagesRadar Score
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2023-42794.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
tomcat-coyote@9.0.73
9.0.81

Open the chart page →

8,636
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2023-42794.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
Apache Tomcat@9.0.80
tomcat@9.0.80-1
tomcat-coyote@9.0.80
8.5.94
8.5.94
9.0.81

Open the chart page →

9,722

Container images carrying it

2 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
atlassian/jira-software:9.7.264a75aa4ec4e
tomcat-coyote@9.0.73
9.0.81
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
Apache Tomcat@9.0.80
tomcat@9.0.80-1
tomcat-coyote@9.0.80
8.5.94
8.5.94
9.0.81
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.