Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-698c-2x4j-g9gq

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

Ссылки

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 9.0.0.M1, <= 9.0.0.M11

9.0.0.M12

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 8.5.0, < 8.5.8

8.5.8

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3

Дефекты

CWE-119
CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

CVSS3: 7.5
redhat
больше 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

CVSS3: 7.5
nvd
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

CVSS3: 7.5
debian
почти 8 лет назад

The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8. ...

EPSS

Процентиль: 40%
0.0018
Низкий

7.5 High

CVSS3

Дефекты

CWE-119
CWE-835