QID 998013
QID 998013: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-43v2-6grp-9pp9)
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-43v2-6grp-9pp9 for updates and patch information.
Vendor References
- GHSA-43v2-6grp-9pp9 -
github.com/advisories/GHSA-43v2-6grp-9pp9
CVEs related to QID 998013
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-43v2-6grp-9pp9 | org.apache.tomcat:tomcat |
|