https://seclists.org/oss-sec/2024/q4/158: CVE-2024-54677: Apache Tomcat: DoS in examples web application
Published Dec 17, 2024
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M1<=11.0.1
Apache Tomcat>=10.1.0-M1<=10.1.33
Apache Tomcat>=9.0.0.M1<=9.9.97
Frequently Asked Questions
1
What is the severity of CVE-2024-54677?
The severity of CVE-2024-54677 is classified as low.
2
Which versions of Apache Tomcat are affected by CVE-2024-54677?
CVE-2024-54677 affects Apache Tomcat versions 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, and 9.0.0.M1 through 9.9.97.
3
How can I mitigate CVE-2024-54677?
To mitigate CVE-2024-54677, upgrade to the latest stable version of Apache Tomcat that is not affected.
4
What type of vulnerability is CVE-2024-54677?
CVE-2024-54677 is a denial of service (DoS) vulnerability in the examples web application of Apache Tomcat.
5
Is there a patch available for CVE-2024-54677?
Yes, a patch is available by updating the Apache Tomcat to a non-affected version.