CVE-2024-23672: Apache Tomcat: WebSocket DoS with incomplete closing handshake
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Other sources
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-websocketto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-websocketto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-websocketto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-websocketto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-websocketto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-websocketto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-websocketto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-websocketto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.99
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23672?
CVE-2024-23672 is classified as a denial of service vulnerability affecting Apache Tomcat.
How do I fix CVE-2024-23672?
To fix CVE-2024-23672, upgrade Apache Tomcat to versions 8.5.99, 9.0.86, 10.1.19, or 11.0.0-M17.
Which Apache Tomcat versions are impacted by CVE-2024-23672?
CVE-2024-23672 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.0-M16, 10.1.0-M1 through 10.1.18, 9.0.0-M1 through 9.0.85, and 8.5.0 through 8.5.98.
What type of vulnerability is CVE-2024-23672?
CVE-2024-23672 is a denial of service vulnerability due to incomplete cleanup of WebSocket connections.
What are the consequences of CVE-2024-23672?
The consequences of CVE-2024-23672 include increased resource consumption, potentially affecting the availability of the affected Apache Tomcat service.