https://seclists.org/oss-sec/2024/q4/159: CVE-2024-54677: Apache Tomcat: DoS in examples web application
Published Dec 17, 2024
·Updated
Affected Software
1 affected component
Apache Tomcat>=9.0.0.M1<9.9.97
Frequently Asked Questions
1
What is the severity of CVE-2024-54677?
CVE-2024-54677 is classified as a DoS vulnerability that can impact the Apache Tomcat examples web application.
2
How do I fix CVE-2024-54677?
To mitigate CVE-2024-54677, upgrade your Apache Tomcat installation to version 9.0.98 or later.
3
What versions of Apache Tomcat are affected by CVE-2024-54677?
CVE-2024-54677 affects Apache Tomcat versions from 9.0.0.M1 through 9.0.97.
4
Can CVE-2024-54677 be exploited remotely?
Yes, CVE-2024-54677 can be exploited remotely, potentially leading to a denial-of-service condition.
5
Is there a workaround for CVE-2024-54677 until I can upgrade?
Currently, the best recommendation is to apply the upgrade to avoid the vulnerabilities associated with CVE-2024-54677.