CVE-2023-42794: The Apache Tomcat Incomplete Cleanup DoS Explained
An unreleased refactoring in Tomcat's bundled Commons FileUpload left temp files undeleted on Windows, risking a disk-exhaustion DoS. Here is what CVE-2023-42794 is and how to fix it.