Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2024-23672

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.

Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

No technical information available.

CWEs:

Software From Fixed in
org.apache.tomcat / tomcat-websocket 11.0.0-M1 11.0.0-M17
org.apache.tomcat / tomcat-websocket 10.1.0-M1 10.1.19
org.apache.tomcat / tomcat-websocket 9.0.0-M1 9.0.86
org.apache.tomcat / tomcat-websocket 8.5.0 8.5.99
org.apache.tomcat.embed / tomcat-embed-websocket 11.0.0-M1 11.0.0-M17
org.apache.tomcat.embed / tomcat-embed-websocket 10.1.0-M1 10.1.19
org.apache.tomcat.embed / tomcat-embed-websocket 9.0.0-M1 9.0.86
org.apache.tomcat.embed / tomcat-embed-websocket 8.5.0 8.5.99
apache / tomcat 11.0.0-milestone1 11.0.0-milestone1.x
apache / tomcat 11.0.0-milestone2 11.0.0-milestone2.x
apache / tomcat 11.0.0-milestone4 11.0.0-milestone4.x
apache / tomcat 11.0.0-milestone3 11.0.0-milestone3.x
apache / tomcat 11.0.0-milestone5 11.0.0-milestone5.x
apache / tomcat 11.0.0-milestone7 11.0.0-milestone7.x
apache / tomcat 8.5.0 8.5.99
apache / tomcat 10.1.0 10.1.19
apache / tomcat 11.0.0-milestone10 11.0.0-milestone10.x
apache / tomcat 11.0.0-milestone11 11.0.0-milestone11.x
apache / tomcat 11.0.0-milestone12 11.0.0-milestone12.x
apache / tomcat 11.0.0-milestone13 11.0.0-milestone13.x
apache / tomcat 11.0.0-milestone14 11.0.0-milestone14.x
apache / tomcat 11.0.0-milestone15 11.0.0-milestone15.x
apache / tomcat 11.0.0-milestone16 11.0.0-milestone16.x
apache / tomcat 11.0.0-milestone6 11.0.0-milestone6.x
apache / tomcat 11.0.0-milestone8 11.0.0-milestone8.x
apache / tomcat 11.0.0-milestone9 11.0.0-milestone9.x
apache / tomcat 9.0.0 9.0.86
debian / debian_linux 10.0 10.0.x
fedoraproject / fedora 39 39.x
fedoraproject / fedora 40 40.x