Bug 2332815 (CVE-2024-54677) - CVE-2024-54677 tomcat: Apache Tomcat: DoS in examples web application [NEEDINFO]
Summary: CVE-2024-54677 tomcat: Apache Tomcat: DoS in examples web application
Keywords:
Status: NEW
Alias: CVE-2024-54677
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-12-17 13:01 UTC by OSIDB Bzimport
Modified: 2025-05-13 15:59 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:
aogburn: needinfo? (prodsec-dev)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:3608 0 None None None 2025-04-07 17:01:45 UTC
Red Hat Product Errata RHSA-2025:3609 0 None None None 2025-04-07 17:01:28 UTC
Red Hat Product Errata RHSA-2025:7497 0 None None None 2025-05-13 15:59:23 UTC

Description OSIDB Bzimport 2024-12-17 13:01:07 UTC
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.

Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Comment 4 errata-xmlrpc 2025-04-07 17:01:27 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2025:3609 https://access.redhat.com/errata/RHSA-2025:3609

Comment 5 errata-xmlrpc 2025-04-07 17:01:43 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 6.1 on RHEL 8
  Red Hat JBoss Web Server 6.1 on RHEL 9

Via RHSA-2025:3608 https://access.redhat.com/errata/RHSA-2025:3608

Comment 9 errata-xmlrpc 2025-05-13 15:59:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:7497 https://access.redhat.com/errata/RHSA-2025:7497


Note You need to log in before you can comment on or make changes to this bug.