Tomcat CVE-2024-23672 - Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
search cancel

Tomcat CVE-2024-23672 - Denial of Service via incomplete cleanup vulnerability in Apache Tomcat

book

Article ID: 371198

calendar_today

Updated On:

Products

DX NetOps

Issue/Introduction


Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

Environment

Spectrum 23.3.8 and earlier

Resolution


This vulnerability is addressed in Spectrum 23.3.9 where Tomcat is updated to 9.0.87.

Additional Information