Junglewise Threat Intelligence

CVE-2020-13935: Apache Tomcat infinite loop in WebSocket payload validation

CVE-2020-13935 · Severity: high · CVSS 7.5 · Published 2022-02-08

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server and application container for Java-based websites. A flaw in how it handles WebSocket communication allows an attacker to send specially crafted messages that cause the server to enter an infinite loop. This can consume all available system resources, leading to a denial-of-service (DoS) where the website or application becomes unavailable to legitimate users.

Technical details

A vulnerability exists in Apache Tomcat's WebSocket implementation (CWE-835) due to improper validation of the payload length in WebSocket frames. An unauthenticated remote attacker can exploit this by sending a WebSocket frame with an invalid payload length, triggering an infinite loop within the server process. Repeated exploitation can exhaust CPU resources, resulting in a complete denial of service. The issue affects versions 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56, and 7.0.27 to 7.0.104. Patches are available in versions 10.0.0-M7, 9.0.37, 8.5.57, and 7.0.105.

Affected products

  • Apache Tomcat 7.0.27 to 7.0.104, 8.5.0 to 8.5.56, 9.0.0.M1 to 9.0.36, 10.0.0-M1 to 10.0.0-M6

Timeline

  • 2020-07-14: advisory: NVD published date
  • 2022-02-08: disclosed: GitHub Advisory published date

References

Related threats