

Release Notes / Version 11.2210
Table Of Contents

Changed multipart request handling from Commons Fileupload to Servlet API

The runtime dependency commons-fileupload:commons-fileupload has been removed in order to prevent vulnerability CVE-2023-24998 . By removing the application property spring.servlet.multipart.enabled=true , the Studio server configuration has been changed from using Commons Fileupload for handling multipart requests to using the Servlet API .

To retain the defaults of the former Commons Fileupload implementation, the following default configurations for the Servlet API implementation have been changed:


Furthermore, the file size threshold has been set to prevent out-of-memory problems in the Studio server:


For further information see the Spring documentation:


Was this article useful?

Search Results

Table Of Contents

Your Internet Explorer is no longer supported.

Please use Mozilla Firefox, Google Chrome, or Microsoft Edge.