Junglewise Threat Intelligence

CVE-2024-54677: Apache Tomcat uncontrolled resource consumption in examples application

CVE-2024-54677 · Severity: medium · CVSS 5.3 · Published 2024-12-17

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server for hosting Java-based applications. A vulnerability in the optional 'examples' web application included with the server could allow an attacker to consume excessive system resources, potentially leading to a denial of service. This could result in the web server becoming unresponsive, affecting the availability of hosted business applications.

Technical details

An uncontrolled resource consumption vulnerability exists in the 'examples' web application bundled with Apache Tomcat. The flaw allows a remote, unauthenticated attacker to trigger excessive resource usage through the examples application, leading to a denial of service (DoS) condition. This vulnerability specifically resides in the optional examples directory and does not affect the core Tomcat server components. The issue is resolved in versions 11.0.2, 10.1.34, and 9.0.98. Organizations can also mitigate the risk by following security best practices and removing the 'webapps/examples/' directory from production environments.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, 9.0.0.M1 through 9.0.97, 8.5.0 through 8.5.100

Timeline

  • 2024-12-17: advisory: GHSA-653p-vg55-5652 published
  • 2024-12-17: disclosed: CVE-2024-54677 disclosed

References