QID 997725
Date Published: 2024-03-18
QID 997725: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-v682-8vv8-vpwr)
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v682-8vv8-vpwr for updates and patch information.
Vendor References
- GHSA-v682-8vv8-vpwr -
github.com/advisories/GHSA-v682-8vv8-vpwr
CVEs related to QID 997725
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v682-8vv8-vpwr | org.apache.tomcat:tomcat |
|