Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 18 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2024-03-13T15:48:42.610Z
Updated: 2024-11-18T21:35:31.746Z
Reserved: 2024-01-19T11:44:18.348Z
Link: CVE-2024-23672
Vulnrichment
Updated: 2024-08-01T23:06:25.345Z
NVD
Status : Awaiting Analysis
Published: 2024-03-13T16:15:29.287
Modified: 2024-11-21T08:58:08.340
Link: CVE-2024-23672
Redhat