vulnerability

Amazon Linux AMI 2: CVE-2024-54677: Security patch for tomcat (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Dec 17, 2024
Added
Mar 4, 2025
Modified
Apr 17, 2025

Description

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.

Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Solutions

amazon-linux-ami-2-upgrade-tomcatamazon-linux-ami-2-upgrade-tomcat-admin-webappsamazon-linux-ami-2-upgrade-tomcat-docs-webappamazon-linux-ami-2-upgrade-tomcat-el-2-2-apiamazon-linux-ami-2-upgrade-tomcat-el-3-0-apiamazon-linux-ami-2-upgrade-tomcat-javadocamazon-linux-ami-2-upgrade-tomcat-jsp-2-2-apiamazon-linux-ami-2-upgrade-tomcat-jsp-2-3-apiamazon-linux-ami-2-upgrade-tomcat-jsvcamazon-linux-ami-2-upgrade-tomcat-libamazon-linux-ami-2-upgrade-tomcat-servlet-3-0-apiamazon-linux-ami-2-upgrade-tomcat-servlet-4-0-apiamazon-linux-ami-2-upgrade-tomcat-webapps
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.