Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10072

Опубликовано: 21 июн. 2019
Источник: redhat
CVSS3: 5.3

Описание

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Меры по смягчению последствий

pki-servlet-container does not use HTTP/2 in its default configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6tomcatOut of support scope
Red Hat Enterprise Linux 6tomcatNot affected
Red Hat Enterprise Linux 7tomcatNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-containerWill not fix
Red Hat Fuse 7tomcatNot affected
Red Hat JBoss BRMS 6tomcatOut of support scope
Red Hat JBoss Data Grid 7tomcatNot affected
Red Hat JBoss Fuse 6tomcatNot affected
Red Hat JBoss Web Server 5tomcatFixedRHSA-2019:393120.11.2019
Red Hat JBoss Web Server 5.2 on RHEL 6jws5-ecjFixedRHSA-2019:392920.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1723708tomcat: HTTP/2 connection window exhaustion on write, incomplete fix of CVE-2019-0199

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS3: 7.5
nvd
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

CVSS3: 7.5
debian
почти 6 лет назад

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 co ...

CVSS3: 7.5
github
почти 6 лет назад

Improper Locking in Apache Tomcat

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3