Junglewise Threat Intelligence

CVE-2024-38286: Apache Tomcat resource exhaustion in TLS handshake

CVE-2024-38286 · Severity: high · CVSS 8.6 · Published 2024-11-07

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely used web server and servlet container, is vulnerable to a denial-of-service attack. An attacker can exploit the secure connection (TLS) handshake process to exhaust the server's memory. This can lead to a complete service crash, preventing legitimate users from accessing hosted applications and potentially disrupting business operations.

Technical details

This vulnerability is classified as an 'Allocation of Resources Without Limits or Throttling' (CWE-770) issue within Apache Tomcat's TLS handshake implementation. Under specific configurations, a remote, unauthenticated attacker can initiate a TLS handshake that causes the server to allocate excessive memory, eventually triggering an OutOfMemoryError (OOM). The attack is carried out over the network and does not require user interaction. The issue has been addressed in versions 11.0.0-M21, 10.1.25, and 9.0.90; older versions like 8.5.x and 7.0.x are also affected but have reached end-of-life.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.0-M20, 10.1.0-M1 through 10.1.24, 9.0.13 through 9.0.89, 8.5.35 through 8.5.100, 7.0.92 through 7.0.109

Timeline

  • 2024-11-07: advisory: GitHub Advisory published
  • 2024-11-07: disclosed: NVD publication date

References