QID 981003

QID 981003: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-m59c-jpc8-m2x4)

An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-m59c-jpc8-m2x4 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981003

    Software Advisories
    Advisory ID Software Component Link
    GHSA-m59c-jpc8-m2x4 org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-m59c-jpc8-m2x4