Uploaded image for project: 'TomEE'
  1. TomEE
  2. TOMEE-4255

Port fix for CVE-2023-44487

    XMLWordPrintableJSON

Details

    • Dependency upgrade
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 9.1.0
    • 9.1.1
    • None
    • None

    Description

      Important: Denial of Service CVE-2023-44487

      Tomcat's HTTP/2 implementation was vulnerable to the rapid reset attack. The denial of service typically manifested as an OutOfMemoryError.

      This was fixed with commit 76bb4bfb.

      This issue was reported to the Tomcat Security Team on 14 September 2023. The issue was made public on 10 October 2023.

      Affects: 10.1.0-M1 to 10.1.13

      Attachments

        Activity

          People

            rzo1 Richard Zowalla
            rzo1 Richard Zowalla
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: