CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Other sources
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
redhat/Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.99 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0-M17 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.19 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.86 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.99
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24549?
CVE-2024-24549 has a severity rating of medium due to its potential to cause denial of service.
How do I fix CVE-2024-24549?
To fix CVE-2024-24549, upgrade Apache Tomcat to version 8.5.99, 9.0.86, 10.1.19, or 11.0.0-M17, depending on your version.
What systems are affected by CVE-2024-24549?
CVE-2024-24549 affects multiple versions of Apache Tomcat, specifically those prior to 8.5.99, 9.0.86, 10.1.19, and 11.0.0-M17.
Is there a workaround for CVE-2024-24549?
Currently, the recommendation is to apply the available patches rather than relying on workarounds for CVE-2024-24549.
What type of attack does CVE-2024-24549 allow?
CVE-2024-24549 allows remote attackers to perform denial of service attacks by sending specially crafted HTTP/2 requests.