Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
High severity
GitHub Reviewed
Published
Feb 8, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Package
Affected versions
>= 10.0.0-M1, <= 10.0.0-M5
>= 9.0.0.M5, < 9.0.36
>= 8.5.1, < 8.5.56
Patched versions
10.0.0-M6
9.0.36
8.5.56
Description
Published by the National Vulnerability Database
Jul 14, 2020
Reviewed
Apr 12, 2021
Published to the GitHub Advisory Database
Feb 8, 2022
Last updated
Feb 1, 2023
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
References