In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.0Upgrade Apache Tomcat to 8.5.13 | Apr 17, 2017 | Apr 17, 2017 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Oct 30, 2017 | Apr 17, 2017 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8 to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.13-0.175.3.21.0.1.0 on Solaris 11.3 | Jun 20, 2017 | Apr 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub