Description: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the stream. The file would never be deleted from disk creating the possibility of an eventual denial of service due to the disk being full. Users are recommended to upgrade to version 9.0.81 onwards or 8.5.94 onwards, which fixes the issue. Broken commit info: Bugfix commit info: https://github.com/apache/tomcat/commit/c99ffc30e95ddc4daede564d08cb5ea2b9a9da65 https://github.com/apache/tomcat/commit/43b882b8a577684498ab9b8851aa0427216784f7 https://github.com/apache/tomcat/commit/44d05d75d696ca10ce251e4e370511e38f20ae75
PR: https://e.gitee.com/openanolis/repos/src-anolis-os/tomcat/pulls/10?tab=files