Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38286

Опубликовано: 23 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. Older, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

A vulnerability was found in Tomcat. Under certain configurations on any platform, this flaw allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

Отчет

CVE-2024-38286 represents an important security issue due to its potential to cause an OutOfMemoryError through the exploitation of the TLS handshake process in Apache Tomcat. This vulnerability specifically impacts configurations using TLS 1.3, which is increasingly adopted for secure communications. The ability for an attacker to trigger an OutOfMemoryError can lead to a denial-of-service (DoS) condition, effectively rendering the application or server inoperable. The issue only affects configurations that utilize TLS 1.3.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 9pki-servlet-engineAffected
Red Hat Enterprise Linux 8tomcatFixedRHSA-2024:569421.08.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportpki-depsFixedRHSA-2024:856729.10.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpki-depsFixedRHSA-2024:849728.10.2024
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicepki-depsFixedRHSA-2024:849728.10.2024
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionspki-depsFixedRHSA-2024:849728.10.2024
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportpki-depsFixedRHSA-2024:857229.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2314686tomcat: Denial of Service in Tomcat

EPSS

Процентиль: 71%
0.00693
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
7 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. Older, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

CVSS3: 8.6
nvd
7 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. Older, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

CVSS3: 8.6
debian
7 месяцев назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

suse-cvrf
9 месяцев назад

Security update for tomcat

CVSS3: 8.6
github
7 месяцев назад

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

EPSS

Процентиль: 71%
0.00693
Низкий

7.5 High

CVSS3