Executive brief
Apache Tomcat is a widely used web server for hosting Java-based applications. A vulnerability in the optional 'examples' web application included with the server could allow an attacker to consume excessive system resources, potentially leading to a denial of service. This could result in the web server becoming unresponsive, affecting the availability of hosted business applications.
Technical details
An uncontrolled resource consumption vulnerability exists in the 'examples' web application bundled with Apache Tomcat. The flaw allows a remote, unauthenticated attacker to trigger excessive resource usage through the examples application, leading to a denial of service (DoS) condition. This vulnerability specifically resides in the optional examples directory and does not affect the core Tomcat server components. The issue is resolved in versions 11.0.2, 10.1.34, and 9.0.98. Organizations can also mitigate the risk by following security best practices and removing the 'webapps/examples/' directory from production environments.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, 9.0.0.M1 through 9.0.97, 8.5.0 through 8.5.100
Timeline
- 2024-12-17: advisory: GHSA-653p-vg55-5652 published
- 2024-12-17: disclosed: CVE-2024-54677 disclosed
References
- https://api.github.com/users/yusuke-koyoshi
- https://github.com/yusuke-koyoshi
- https://api.github.com/users/yusuke-koyoshi/gists%7B/gist_id%7D
- https://api.github.com/users/yusuke-koyoshi/repos
- https://avatars.githubusercontent.com/u/92022336?v=4
- https://api.github.com/users/yusuke-koyoshi/events%7B/privacy%7D