Description
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Classifieds & Directory Pro Unspecified Vulnerability (1.6.5)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3541)
WordPress Plugin Popup by Supsystic Cross-Site Request Forgery (1.7.8)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Request Forgery (4.4.3)