QID 150835
Date Published: 2024-03-18
QID 150835: Apache Tomcat Multiple Denial of Service (DoS) Vulnerabilities (CVE-2024-23672, CVE-2024-24549)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
Affected versions of Apache Tomcat has multiple vulnerabilities:
CVE-2024-23672: It was possible for a WebSocket client to keep a WebSocket connection
open leading to increased resource consumption.
CVE-2024-24549: When processing an HTTP/2 request, if the request exceeded any of the
configured limits for headers, the associated HTTP/2 stream was not
reset until after all of the headers had been processed.
Affected Versions:
Apache Tomcat 11.0.0-M1 to 11.0.0-M16
Apache Tomcat 10.1.0-M1 to 10.1.18
Apache Tomcat 9.0.0-M1 to 9.0.85
Apache Tomcat 8.5.0 to 8.5.98
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation of the vulnerability can allow an attacker to trigger a DoS.
Apache Tomcat 11.0.0-M17 or later
Apache Tomcat 10.1.19 or later
Apache Tomcat 9.0.86 or later
Apache Tomcat 8.5.99 or later
For more information on this vulnerability please refer Apache Tomcat 8 Security Advisory, Apache Tomcat 9 Security Advisory, Apache Tomcat 10 Security Advisory, Apache Tomcat 11 Security Advisory.
- Apache Tomcat 10 -
tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.19 - Apache Tomcat 11 -
tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M17 - Apache Tomcat 8 -
tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.99 - Apache Tomcat 9 -
tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.86
CVEs related to QID 150835
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|
||
| Apache Tomcat |
|
||
| Apache Tomcat |
|
||
| Apache Tomcat |
|