BIT-tomcat-2020-13935
Dashboard / Vulnerabilities / BIT-tomcat-2020-13935
BIT-tomcat-2020-13935
Summary:
Details: The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
References: http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html, http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html, https://kc.mcafee.com/corporate/index?page=content&id=SB10332, https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E, https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E, https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html, https://security.netapp.com/advisory/ntap-20200724-0003/, https://usn.ubuntu.com/4448-1/, https://usn.ubuntu.com/4596-1/, https://www.debian.org/security/2020/dsa-4727, https://www.oracle.com//security-alerts/cpujul2021.html, https://www.oracle.com/security-alerts/cpuApr2021.html, https://www.oracle.com/security-alerts/cpuapr2022.html, https://www.oracle.com/security-alerts/cpujan2021.html, https://www.oracle.com/security-alerts/cpujan2022.html, https://www.oracle.com/security-alerts/cpuoct2020.html, https://www.oracle.com/security-alerts/cpuoct2021.html, https://nvd.nist.gov/vuln/detail/CVE-2020-13935
Affected packages
Package
Name: tomcat
Purl: pkg:bitnami/tomcat
Affected ranges
Type: SEMVER
Events:
