Bug 2295651 (CVE-2024-34750)

Summary: CVE-2024-34750 tomcat: Improper Handling of Exceptional Conditions
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: csutherl, ecrosby, jclere, jwakely, pjindal, plodge, prodsec-dev, sbalasub, szappis
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This issue led to a miscounting of active HTTP/2 streams, which in turn led to using an incorrect infinite timeout that allowed connections to remain open that should have been closed.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2295705    
Bug Blocks:    

Description OSIDB Bzimport 2024-07-03 20:41:16 UTC
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.

Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.

Comment 4 errata-xmlrpc 2024-08-06 10:49:19 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2024:5025 https://access.redhat.com/errata/RHSA-2024:5025

Comment 5 errata-xmlrpc 2024-08-06 10:49:42 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 5.8 on RHEL 7
  Red Hat JBoss Web Server 5.8 on RHEL 8
  Red Hat JBoss Web Server 5.8 on RHEL 9

Via RHSA-2024:5024 https://access.redhat.com/errata/RHSA-2024:5024

Comment 6 errata-xmlrpc 2024-08-06 11:07:18 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2024:4977 https://access.redhat.com/errata/RHSA-2024:4977

Comment 7 errata-xmlrpc 2024-08-06 11:07:46 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 6.0 on RHEL 8
  Red Hat JBoss Web Server 6.0 on RHEL 9

Via RHSA-2024:4976 https://access.redhat.com/errata/RHSA-2024:4976

Comment 10 errata-xmlrpc 2024-08-21 11:48:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2024:5694 https://access.redhat.com/errata/RHSA-2024:5694

Comment 11 errata-xmlrpc 2024-08-21 11:49:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2024:5695 https://access.redhat.com/errata/RHSA-2024:5695

Comment 12 errata-xmlrpc 2024-08-21 11:51:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:5693 https://access.redhat.com/errata/RHSA-2024:5693

Comment 13 errata-xmlrpc 2024-08-21 11:54:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:5696 https://access.redhat.com/errata/RHSA-2024:5696

Comment 14 Alicent Hightower 2024-09-11 04:01:31 UTC Comment hidden (spam)
Comment 15 bonitacaily 2024-09-30 09:07:03 UTC Comment hidden (spam)
Comment 16 Jsmes Bond 2025-01-15 06:28:14 UTC Comment hidden (spam)
Comment 17 Jsmes Bond 2025-01-15 06:29:46 UTC Comment hidden (spam)
Comment 18 Jsmes Bond 2025-01-15 06:31:12 UTC Comment hidden (spam)
Comment 19 Hookz 2025-03-16 18:42:24 UTC Comment hidden (spam)
Comment 20 John H Smith 2025-03-26 04:10:27 UTC Comment hidden (spam)
Comment 21 Eric Payne 2025-03-27 22:03:07 UTC Comment hidden (spam)
Comment 22 nancy266 2025-03-31 07:58:54 UTC Comment hidden (spam)