First published: Wed Mar 13 2024(Updated: )
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/Apache Tomcat | <11.0.0 | 11.0.0 |
redhat/Apache Tomcat | <10.1.19 | 10.1.19 |
redhat/Apache Tomcat | <9.0.86 | 9.0.86 |
redhat/Apache Tomcat | <8.5.99 | 8.5.99 |
maven/org.apache.tomcat.embed:tomcat-embed-websocket | >=8.5.0<=8.5.98 | 8.5.99 |
maven/org.apache.tomcat.embed:tomcat-embed-websocket | >=9.0.0-M1<=9.0.85 | 9.0.86 |
maven/org.apache.tomcat.embed:tomcat-embed-websocket | >=10.1.0-M1<=10.1.18 | 10.1.19 |
maven/org.apache.tomcat.embed:tomcat-embed-websocket | >=11.0.0-M1<=11.0.0-M16 | 11.0.0-M17 |
maven/org.apache.tomcat:tomcat-websocket | >=8.5.0<=8.5.98 | 8.5.99 |
maven/org.apache.tomcat:tomcat-websocket | >=9.0.0-M1<=9.0.85 | 9.0.86 |
maven/org.apache.tomcat:tomcat-websocket | >=10.1.0-M1<=10.1.18 | 10.1.19 |
maven/org.apache.tomcat:tomcat-websocket | >=11.0.0-M1<=11.0.0-M16 | 11.0.0-M17 |
Tomcat | >=8.5.0<8.5.99 | |
Tomcat | >=9.0.0<9.0.86 | |
Tomcat | >=10.1.0<10.1.19 | |
Tomcat | =11.0.0-milestone1 | |
Tomcat | =11.0.0-milestone10 | |
Tomcat | =11.0.0-milestone11 | |
Tomcat | =11.0.0-milestone12 | |
Tomcat | =11.0.0-milestone13 | |
Tomcat | =11.0.0-milestone14 | |
Tomcat | =11.0.0-milestone15 | |
Tomcat | =11.0.0-milestone16 | |
Tomcat | =11.0.0-milestone2 | |
Tomcat | =11.0.0-milestone3 | |
Tomcat | =11.0.0-milestone4 | |
Tomcat | =11.0.0-milestone5 | |
Tomcat | =11.0.0-milestone6 | |
Tomcat | =11.0.0-milestone7 | |
Tomcat | =11.0.0-milestone8 | |
Tomcat | =11.0.0-milestone9 | |
Debian Linux | =10.0 | |
Red Hat Fedora | =39 | |
Red Hat Fedora | =40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23672 is classified as a denial of service vulnerability affecting Apache Tomcat.
To fix CVE-2024-23672, upgrade Apache Tomcat to versions 8.5.99, 9.0.86, 10.1.19, or 11.0.0-M17.
CVE-2024-23672 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.0-M16, 10.1.0-M1 through 10.1.18, 9.0.0-M1 through 9.0.85, and 8.5.0 through 8.5.98.
CVE-2024-23672 is a denial of service vulnerability due to incomplete cleanup of WebSocket connections.
The consequences of CVE-2024-23672 include increased resource consumption, potentially affecting the availability of the affected Apache Tomcat service.