QID 996831
Date Published: 2024-01-24
QID 996831: Java (Maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-wf5v-jhxj-q632)
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wf5v-jhxj-q632 for updates and patch information.
Vendor References
- GHSA-wf5v-jhxj-q632 -
github.com/advisories/GHSA-wf5v-jhxj-q632
CVEs related to QID 996831
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wf5v-jhxj-q632 | org.apache.tomcat.embed:tomcat-embed-core |
|