Bug 2269608 (CVE-2024-23672)
Summary: | CVE-2024-23672 Apache Tomcat: WebSocket DoS with incomplete closing handshake | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Zack Miele <zmiele> |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | arsingh, ben.argyle, csutherl, jclere, pjindal, plodge, szappis |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Apache Tomcat 11.0.0-M17, Apache Tomcat 10.1.19, Apache Tomcat 9.0.86, Apache Tomcat 8.5.99 | Doc Type: | If docs needed, set a value |
Doc Text: |
A denial of service (DoS) vulnerability present in the Apache Tomcat package arises from an incomplete cleanup process. Specifically, WebSocket clients can perpetuate WebSocket connections without proper termination, thereby causing a sustained drain on system resources. This vulnerability facilitates the exploitation of Apache Tomcat servers, leading to a scenario where excessive resource consumption occurs due to the prolonged existence of these open WebSocket connections. As a consequence, the server's performance may degrade significantly, resulting in potential service disruption or unresponsiveness.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2269612 | ||
Bug Blocks: | 2270596 |
Description
Zack Miele
2024-03-14 21:00:30 UTC
Created tomcat tracking bugs for this issue: Affects: fedora-all [bug 2269612] This issue has been addressed in the following products: Red Hat JBoss Web Server 5.8 on RHEL 7 Red Hat JBoss Web Server 5.8 on RHEL 8 Red Hat JBoss Web Server 5.8 on RHEL 9 Via RHSA-2024:1913 https://access.redhat.com/errata/RHSA-2024:1913 This issue has been addressed in the following products: Red Hat JBoss Web Server Via RHSA-2024:1914 https://access.redhat.com/errata/RHSA-2024:1914 This issue has been addressed in the following products: Red Hat JBoss Web Server 6.0 on RHEL 8 Red Hat JBoss Web Server 6.0 on RHEL 9 Via RHSA-2024:1916 https://access.redhat.com/errata/RHSA-2024:1916 This issue has been addressed in the following products: Red Hat JBoss Web Server Via RHSA-2024:1917 https://access.redhat.com/errata/RHSA-2024:1917 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:3308 https://access.redhat.com/errata/RHSA-2024:3308 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:3307 https://access.redhat.com/errata/RHSA-2024:3307 Is there a fix coming for Red Hat Enterprise Linux 8, please? This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3666 https://access.redhat.com/errata/RHSA-2024:3666 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:3814 https://access.redhat.com/errata/RHSA-2024:3814 |