Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption Vulnerability Affects Apache Tomcat

CVE-2024-34750
Currently unrated 🤨

Key Information

Vendor
Apache
Status
Apache Tomcat
Vendor
CVE Published:
3 July 2024

Badges

👾 Exploit Exists📰 News Worthy

Summary

The vulnerability CVE-2024-34750 affects Apache Tomcat, an open-source server, and can be exploited to overload the server's computing resources, leading to a Denial of Service (DoS) attack. The vulnerability affects various versions of Apache Tomcat, and it was discovered directly by the Tomcat security team. The issue stems from an improper handling of HTTP/2 streams, resulting in an incorrect infinite timeout, which allows connections to remain open when they should have been closed. The impact of this vulnerability can be severe, causing service slowdowns or outages. It is recommended to update Tomcat to the patched versions to mitigate the risk. There is a high urgency in addressing this vulnerability due to its potential impact on service availability.

Affected Version(s)

Apache Tomcat <= 11.0.0-M20

Apache Tomcat <= 10.1.24

Apache Tomcat <= 9.0.89

News Articles

Timeline

  • 👾

    Exploit exists.

  • First article discovered by Red Hot Cyber

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database3 News Article(s)

Credit

devme4f from VNPT-VCI
.