PT-2024-5694 · Apache+12 · Apache Tomcat+16
Devme4F
·
Published
2024-06-19
·
Updated
2026-03-26
·
CVE-2024-34750
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 11.0.0-M1 through 11.0.0-M20
Apache Tomcat versions 10.1.0-M1 through 10.1.24
Apache Tomcat versions 9.0.0-M1 through 9.0.89
Description
The issue is related to the improper handling of exceptional conditions and uncontrolled resource consumption in Apache Tomcat when processing an HTTP/2 stream. This led to a miscounting of active HTTP/2 streams, which in turn led to the use of an incorrect infinite timeout, allowing connections to remain open that should have been closed. It is estimated that over 50,300 services are potentially affected.
Recommendations
To resolve the issue, users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
For versions 11.0.0-M1 through 11.0.0-M20, upgrade to version 11.0.0-M21.
For versions 10.1.0-M1 through 10.1.24, upgrade to version 10.1.25.
For versions 9.0.0-M1 through 9.0.89, upgrade to version 9.0.90.
Fix
Improper Handling of Exceptional Conditions
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Bamboo
Bitbucket
Centos
Confluence
Debian
Jira
Jira Service Management Server
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu