First published: Wed Mar 13 2024(Updated: )
Apache Tomcat is vulnerable to a denial of service, caused by improper input validation by the HTTP/2 header. By sending specially crafted HTTP/2 requests, a remote attacker could exploit this vulnerability to cause a denial of service condition.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.tomcat:tomcat-coyote | >=8.5.0<=8.5.98 | 8.5.99 |
maven/org.apache.tomcat:tomcat-coyote | >=9.0.0-M1<=9.0.85 | 9.0.86 |
maven/org.apache.tomcat:tomcat-coyote | >=10.1.0-M1<=10.1.18 | 10.1.19 |
maven/org.apache.tomcat:tomcat-coyote | >=11.0.0-M1<=11.0.0-M16 | 11.0.0-M17 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=11.0.0-M1<=11.0.0-M16 | 11.0.0-M17 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=10.1.0-M1<=10.1.18 | 10.1.19 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=9.0.0-M1<=9.0.85 | 9.0.86 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.5.0<=8.5.98 | 8.5.99 |
redhat/Apache Tomcat | <11.0.0 | 11.0.0 |
redhat/Apache Tomcat | <10.1.19 | 10.1.19 |
redhat/Apache Tomcat | <9.0.86 | 9.0.86 |
redhat/Apache Tomcat | <8.5.99 | 8.5.99 |
IBM IBM® Db2® on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data | <=v3.5 through refresh 10v4.0 through refresh 9v4.5 through refresh 3v4.6 through refresh 6v4.7 through refresh 4v4.8 through refresh 4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.