REDHAT-BUG-2362783: Input Validation
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.
This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.
Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2362783?
The severity of REDHAT-BUG-2362783 is high due to the potential for an OutOfMemoryException leading to denial of service.
How do I fix REDHAT-BUG-2362783?
To fix REDHAT-BUG-2362783, update Apache Tomcat to the latest version beyond 9.0.102, 10.1.39, or 11.0.5, depending on your currently used version.
What systems are affected by REDHAT-BUG-2362783?
Affected systems by REDHAT-BUG-2362783 include Apache Tomcat versions 9.0.76 to 9.0.102, 10.1.10 to 10.1.39, and 11.0.0-M2 to 11.0.5.
What is the cause of REDHAT-BUG-2362783?
REDHAT-BUG-2362783 is caused by improper input validation and incorrect error handling for invalid HTTP priority headers, leading to a memory leak.
What are the symptoms of REDHAT-BUG-2362783?
Symptoms of REDHAT-BUG-2362783 include excessive memory consumption and potential application crashes due to OutOfMemoryExceptions.