https://seclists.org/oss-sec/2024/q1/225: CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS
Published Mar 13, 2024
·Updated
Affected Software
1 affected component
Apache Tomcat
Frequently Asked Questions
1
What is the severity of CVE-2024-24549?
The severity of CVE-2024-24549 is classified as high due to its potential to cause a denial of service in Apache Tomcat.
2
How do I fix CVE-2024-24549?
To fix CVE-2024-24549, update Apache Tomcat to the latest version where the vulnerability has been patched.
3
What versions of Apache Tomcat are affected by CVE-2024-24549?
CVE-2024-24549 affects multiple versions of Apache Tomcat that utilize HTTP/2 header handling.
4
What is the impact of CVE-2024-24549?
The impact of CVE-2024-24549 is that it could lead to a denial of service, disrupting the availability of services dependent on Apache Tomcat.
5
Is CVE-2024-24549 actively being exploited?
As of now, there are no reports of active exploitation for CVE-2024-24549, but monitoring is advised.