Description
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service.
Remediation
References
https://github.com/manolo/gwtupload/issues/33
https://logicaltrust.net/blog/2020/02/gwt-upload.html
Related Vulnerabilities
CVE-2020-13654 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-26541 Vulnerability in npm package gitlog
CVE-2022-43404 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-46366 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2023-47321 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web