CVE-2017-5650Improper Resource Shutdown or Release in Software Foundation Apache Tomcat

Severity
7.5HIGHNVD
EPSS
23.4%
top 4.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 13

Description

In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/tomcat14 versions+13
CVEListV5apache_software_foundation/apache_tomcat8.5.0 to 8.5.12, 9.0.0.M1 to 9.0.0.M18+1

🔴Vulnerability Details

3
OSV
Improper Resource Shutdown or Release in Apache Tomcat2022-05-13
GHSA
Improper Resource Shutdown or Release in Apache Tomcat2022-05-13
CVEList
CVE-2017-5650: In Apache Tomcat 92017-04-17

📋Vendor Advisories

3
Red Hat
tomcat: Handling of HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection2017-04-10
Debian
CVE-2017-5650: tomcat9 - In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an H...2017
Apache
Apache tomcat: CVE-2017-5650

💬Community

1
Bugzilla
CVE-2017-5650 tomcat: Handling of HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection2017-04-11
CVE-2017-5650 — Improper Resource Shutdown or Release | cvebase