Executive brief
Apache Tomcat is a widely used web server for hosting Java-based applications. A flaw in its handling of modern web traffic (HTTP/2) allows an attacker to overwhelm the server by keeping connections open without sending data. This can lead to a complete service outage, preventing legitimate users from accessing hosted applications.
Technical details
The HTTP/2 implementation in Apache Tomcat fails to properly limit the number of SETTINGS frames and allows clients to maintain open streams without active data transfer. By exploiting the Servlet API's blocking I/O, a remote attacker can keep these streams open indefinitely, eventually exhausting the server's thread pool. This results in a Denial of Service (DoS) condition where the server can no longer process new requests. The vulnerability is patched in versions 9.0.16 and 8.5.38.
Affected products
- Apache Tomcat 9.0.0.M1 to 9.0.14, 8.5.0 to 8.5.37
Timeline
- 2019-04-10: advisory: NVD publication date
- 2020-06-15: disclosed: GitHub Advisory published