Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4hg-rmq2-52q9

Опубликовано: 26 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Locking in Apache Tomcat

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Ссылки

Пакеты

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.0.M1, < 9.0.20

9.0.20

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.5.0, < 8.5.41

8.5.41

EPSS

Процентиль: 99%
0.71534
Высокий

7.5 High

CVSS3

Дефекты

CWE-667

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS3: 5.3
redhat
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS3: 7.5
nvd
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS3: 7.5
debian
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 co ...

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 99%
0.71534
Высокий

7.5 High

CVSS3

Дефекты

CWE-667