These are all security issues fixed in the apache-commons-fileupload-1.4-1.9 package on the GA media of openSUSE Tumbleweed.
{ "binaries": [ { "apache-commons-fileupload": "1.4-1.9", "apache-commons-fileupload-javadoc": "1.4-1.9" } ] }