oss-sec: CVE-2020-11996 Apache Tomcat HTTP/2 Denial of Service

added 27.06.2020 09:39

by Mark Thomas from seclists.org

From: Mark Thomas <markt () apache org> Date: Thu, 25 Jun 2020 22:58:40 +0100 CVE-2020-11996 Apache Tomcat HTTP/2 Denial of Service Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 10.0.0-M1 to 10.0.0-M5 Apache Tomcat 9.0.0.

M1 to 9.0.35 Apache Tomcat 8.5.0 to 8.5.55 Description: A specially crafted sequence of HTTP/2 requests could trigger high CPU usage for several seconds.

If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.

Mitigation: - Upgrade to Apache Tomcat 10.0.0-M6 or later - Upgrade to Apache Tomcat 9.0.36 or later - Upgrade to Apache Tomcat 8.5.56 or later Credit: This issue was reported publicly via the Apache Tomcat Users mailing list without reference to the potential for DoS.

The DoS risks were identified by the Apache Tomcat Security Team.