Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2017-5650

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P

CWEs:

Software From Fixed in
apache / tomcat 8.5.2 8.5.2.x
apache / tomcat 8.5.9 8.5.9.x
apache / tomcat 8.5.4 8.5.4.x
apache / tomcat 8.5.0 8.5.0.x
apache / tomcat 8.5.10 8.5.10.x
apache / tomcat 8.5.5 8.5.5.x
apache / tomcat 8.5.3 8.5.3.x
apache / tomcat 8.5.6 8.5.6.x
apache / tomcat 8.5.7 8.5.7.x
apache / tomcat 8.5.8 8.5.8.x
apache / tomcat 8.5.12 8.5.12.x
apache / tomcat 8.5.11 8.5.11.x
apache / tomcat 8.5.1 8.5.1.x
org.apache.tomcat / tomcat 9.0.0.M1 9.0.0.M19
org.apache.tomcat / tomcat 8.5.0 8.5.13
apache / tomcat 9.0.0-milestone1 9.0.0-milestone1.x
apache / tomcat 9.0.0-milestone10 9.0.0-milestone10.x
apache / tomcat 9.0.0-milestone11 9.0.0-milestone11.x
apache / tomcat 9.0.0-milestone12 9.0.0-milestone12.x
apache / tomcat 9.0.0-milestone13 9.0.0-milestone13.x
apache / tomcat 9.0.0-milestone14 9.0.0-milestone14.x
apache / tomcat 9.0.0-milestone15 9.0.0-milestone15.x
apache / tomcat 9.0.0-milestone16 9.0.0-milestone16.x
apache / tomcat 9.0.0-milestone17 9.0.0-milestone17.x
apache / tomcat 9.0.0-milestone18 9.0.0-milestone18.x
apache / tomcat 9.0.0-milestone2 9.0.0-milestone2.x
apache / tomcat 9.0.0-milestone3 9.0.0-milestone3.x
apache / tomcat 9.0.0-milestone4 9.0.0-milestone4.x
apache / tomcat 9.0.0-milestone5 9.0.0-milestone5.x
apache / tomcat 9.0.0-milestone6 9.0.0-milestone6.x
apache / tomcat 9.0.0-milestone7 9.0.0-milestone7.x
apache / tomcat 9.0.0-milestone8 9.0.0-milestone8.x
apache / tomcat 9.0.0-milestone9 9.0.0-milestone9.x