DescriptionArun Babu Neelicattu
2014-06-02 15:28:15 UTC
A regression was introduced in revision 1519838 (released with Apache Tomcat 8.0.0-RC2) that caused AJP requests to hang if an explicit content length of zero was set on the request. The hanging request consumed a request processing thread which could lead to a denial of service.
Affects:
Apache Tomcat 8.0.0-RC2 to 8.0.3
References:
http://tomcat.apache.org/security-8.html
Comment 1Arun Babu Neelicattu
2014-06-02 15:31:18 UTC
Statement:
This flaw does not affect Apache Tomcat as shipped by any Red Hat product as it was introduced in Apache Tomcat 8.0.0-RC2 and did not affect earlier versions.