RE: CVE-2023-28709 incomplete fix

2023-07-12 Thread Prodan, Andreea Adriana
023 13:23:32 Prodan, Andreea Adriana : > Hello, > > In regard to > CVE-2023-28709<http://htt/ > ps%3A%2F%2Fcve.mitre.org%2Fcgi-bin%2Fcvename.cgi%3Fname%3DCVE-2023-287 > 09&data=05%7C01%7Candreea.prodan%40siemens.com%7C0ccf59eec5024b4d386b0 > 8db830de352%7C38ae3b

CVE-2023-28709 incomplete fix

2023-07-12 Thread Prodan, Andreea Adriana
Hello, In regard to CVE-2023-28709 we would like to know if the vulnerability caused by the incomplete fix, "If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string param