openSUSE-SU-2020:1051Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html CVE-2020-11996
HIGH
Uncontrolled Resource Consumption in Apache Tomcat
Record summary
CVE-2020-11996 has a selected CVSS score of 7.5 (high).
Description
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Description source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Apache TomcatBrowse Apache / Apache Tomcat | CVE List | 10.0.0-M1 to 10.0.0-M5 | affected |
| 9.0.0.M1 to 9.0.35 | affected | ||
| 8.5.0 to 8.5.55 | affected | ||
org.apache.tomcat.embed:tomcat-embed-coreBrowse Maven / org.apache.tomcat.embed:tomcat-embed-core | GitHub Advisory | 10.0.0-M1 to < 10.0.0-M5 · Fixed in 10.0.0-M5 | affected |
| 9.0.0.M1 to < 9.0.35 · Fixed in 9.0.35 | affected | ||
| 8.5.0 to < 8.5.55 · Fixed in 8.5.55 | affected | ||
org.apache.tomcat:tomcatBrowse Maven / org.apache.tomcat:tomcat | GitHub Advisory | 10.0.0-M1 to < 10.0.0-M5 · Fixed in 10.0.0-M5 | affected |
| 9.0.0.M1 to < 9.0.35 · Fixed in 9.0.35 | affected | ||
| 8.5.0 to < 8.5.55 · Fixed in 8.5.55 | affected |
References
Showing 12 of 47openSUSE-SU-2020:1063Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html github.com
https://github.com/apache/tomcat github.com
https://github.com/apache/tomcat/commit/9434a44d3449d620b1be70206819f8275b4a7509 github.com
https://github.com/apache/tomcat/commit/9a0231683a77e2957cea0fdee88b193b30b0c976 github.com
https://github.com/apache/tomcat/commit/c8acd2ab7371e39aeca7c306f3b5380f00afe552 [tomcat-users] 20201008 Is Tomcat7 supports HTTP2mailing list
https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79%40%3Cusers.tomcat.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/r2529016c311ce9485e6f173446d469600fdfbb94dccadfcd9dfdac79@%3Cusers.tomcat.apache.org%3E [ofbiz-notifications] 20200703 [jira] [Commented] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)mailing list
https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd%40%3Cnotifications.ofbiz.apache.org%3E lists.apache.org
https://lists.apache.org/thread.html/r3ea96d8f36dd404acce83df8aeb22a9e807d6c13ca9c5dec72f872cd@%3Cnotifications.ofbiz.apache.org%3E lists.apache.orgConfirmation
https://lists.apache.org/thread.html/r5541ef6b6b68b49f76fc4c45695940116da2bcbe0312ef204a00a2e0%40%3Cannounce.tomcat.apache.org%3E [ofbiz-notifications] 20210301 [jira] [Updated] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)mailing list
https://lists.apache.org/thread.html/r5a4f80a6acc6607d61dae424b643b594c6188dd4e1eff04705c10db2%40%3Cnotifications.ofbiz.apache.org%3E