7.5

CVE-2024-24549

Apache Tomcat: HTTP/2 header handling DoS

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 8.5.0 < 8.5.99
Apache ≫ Tomcat Version >= 9.0.0 < 9.0.86
Apache ≫ Tomcat Version >= 10.1.0 < 10.1.19
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone12
Apache ≫ Tomcat Version 11.0.0 Update milestone13
Apache ≫ Tomcat Version 11.0.0 Update milestone14
Apache ≫ Tomcat Version 11.0.0 Update milestone15
Apache ≫ Tomcat Version 11.0.0 Update milestone16
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 39
Fedoraproject ≫ Fedora Version 40
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.07% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/
Third Party Advisory
https://security.netapp.com/advisory/ntap-20240402-0002/
Third Party Advisory
http://www.openwall.com/lists/oss-security/2024/03/13/3
Mailing List
https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg
Vendor Advisory