Executive brief
Apache Tomcat, a widely used web server and servlet container, is vulnerable to a denial-of-service attack. An attacker can exploit the secure connection (TLS) handshake process to exhaust the server's memory. This can lead to a complete service crash, preventing legitimate users from accessing hosted applications and potentially disrupting business operations.
Technical details
This vulnerability is classified as an 'Allocation of Resources Without Limits or Throttling' (CWE-770) issue within Apache Tomcat's TLS handshake implementation. Under specific configurations, a remote, unauthenticated attacker can initiate a TLS handshake that causes the server to allocate excessive memory, eventually triggering an OutOfMemoryError (OOM). The attack is carried out over the network and does not require user interaction. The issue has been addressed in versions 11.0.0-M21, 10.1.25, and 9.0.90; older versions like 8.5.x and 7.0.x are also affected but have reached end-of-life.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.0-M20, 10.1.0-M1 through 10.1.24, 9.0.13 through 9.0.89, 8.5.35 through 8.5.100, 7.0.92 through 7.0.109
Timeline
- 2024-11-07: advisory: GitHub Advisory published
- 2024-11-07: disclosed: NVD publication date
References
- https://api.github.com/users/hara-satoshi-ymr
- https://github.com/hara-satoshi-ymr
- https://api.github.com/users/hara-satoshi-ymr/gists%7B/gist_id%7D
- https://api.github.com/users/hara-satoshi-ymr/repos
- https://avatars.githubusercontent.com/u/219617739?v=4
- https://api.github.com/users/hara-satoshi-ymr/events%7B/privacy%7D