https://seclists.org/oss-sec/2024/q3/264: CVE-2024-38286: Apache Tomcat: Denial of Service
Published Sep 23, 2024
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M1<=11.0.0-M20
Apache Tomcat>=10.1.0-M1<=10.1.24
Apache Tomcat>=9.0.13<=9.0.89
Frequently Asked Questions
1
What is the severity of CVE-2024-38286?
CVE-2024-38286 has a moderate severity rating as it can lead to a Denial of Service in affected Apache Tomcat versions.
2
How do I fix CVE-2024-38286?
To fix CVE-2024-38286, upgrade to Apache Tomcat versions 11.0.0-M21 or later, 10.1.25 or later, or 9.0.90 or later.
3
Which versions of Apache Tomcat are affected by CVE-2024-38286?
CVE-2024-38286 affects Apache Tomcat versions 11.0.0-M1 to M20, 10.1.0-M1 to 10.1.24, and 9.0.13 to 9.0.89.
4
What type of vulnerability is CVE-2024-38286?
CVE-2024-38286 is identified as a Denial of Service vulnerability affecting Apache Tomcat.
5
Who reported CVE-2024-38286?
CVE-2024-38286 was reported by Ozaki from North Grid Corporation.