CVE-2020-13934
published 2020-07-14CVE-2020-13934: An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the…
PriorityP354high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
64.12%
99.1th percentile
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | 8.5.1 – 8.5.56 | — |
| apache | tomcat | 9.0.1 – 9.0.36 | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat9 | < tomcat9 9.0.37-1 (bookworm) | tomcat9 9.0.37-1 (bookworm) |
| netapp | oncommand_system_manager | 3.0.0 – 3.1.3 | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_instant_messaging_server | — | — |
| oracle | fmw_platform | — | — |
| oracle | fmw_platform | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | mysql_enterprise_monitor | <= 8.0.21 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit requires an h2c (HTTP/2 cleartext) direct connection upgrade from HTTP/1.1 to HTTP/2; monitor for repeated h2c upgrade requests that do not properly release HTTP/1.1 processors, potentially leading to OutOfMemoryException on the server. ↗
- →Vulnerable Apache Tomcat versions: 10.0.0-M1 through 10.0.0-M6, 9.0.0.M5 through 9.0.36, and 8.5.1 through 8.5.56. Detection should flag these version ranges running with HTTP/2 enabled. ↗
- →The fix for Tomcat 8.5 is in commit 923d8345; presence of this commit (or its absence) can be used to determine patch status on Tomcat 8.5 instances. ↗
- →Upstream fix commits can be used to verify patch status: Tomcat 10.0 fix at c9167ae30f3b03b112f3d81772e3450b7d0e6a25, Tomcat 9.0 fix at 172977f04a5215128f1e278a688983dcd230f399, Tomcat 8.5 fix at 923d834500802a61779318911d7898bd85fc950e. ↗
- ·HTTP/2 must be enabled on the Tomcat instance for this vulnerability to be exploitable; configurations without HTTP/2 enabled are not affected. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
ghsa·2022-02-08
CVE-2020-13934 [HIGH] CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
OSV
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
osv·2022-02-08
CVE-2020-13934 [HIGH] Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
OSV
tomcat9 vulnerabilities
osv·2020-10-21·CVSS 7.5
CVE-2020-11996 [HIGH] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat did not properly manage HTTP/2 streams. An
attacker could possibly use this to cause Tomcat to consume resources,
resulting in a denial of service. (CVE-2020-11996)
It was discovered that Tomcat did not properly release the HTTP/1.1
processor after the upgrade to HTTP/2. An attacker could possibly use this
to generate an OutOfMemoryException, resulting in a denial of service.
(CVE-2020-13934)
It was discovered that Tomcat did not properly validate the payload length
in a WebSocket frame. An attacker could possibly use this to trigger an
infinite loop, resulting in a denial of service. (CVE-2020-13935)
It was discovered that Tomcat did not properly deserialize untrusted data.
An attacker could possibly use this issue to execute arbit
OSV
CVE-2020-13934: An h2c direct connection to Apache Tomcat 10
osv·2020-07-14·CVSS 7.5
CVE-2020-13934 [HIGH] CVE-2020-13934: An h2c direct connection to Apache Tomcat 10
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Red Hat
Tomcat: HTTP/2 header handling DoS
vendor_redhat·2024-03-13·CVSS 7.5
CVE-2024-24549 [HIGH] CWE-20 Tomcat: HTTP/2 header handling DoS
Tomcat: HTTP/2 header handling DoS
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
A vulnerability was found in the Tomcat package due to its handling of HTTP/2 requests. Specifically, when an HTTP/2 request surpasses the predetermined lim
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2020-10-21·CVSS 7.5
CVE-2020-9484 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not properly manage HTTP/2 streams. An
attacker could possibly use this to cause Tomcat to consume resources,
resulting in a denial of service. (CVE-2020-11996)
It was discovered that Tomcat did not properly release the HTTP/1.1
processor after the upgrade to HTTP/2. An attacker could possibly use this
to generate an OutOfMemoryException, resulting in a denial of service.
(CVE-2020-13934)
It was discovered that Tomcat did not properly validate the payload length
in a WebSocket frame. An attacker could possibly use this to trigger an
infinite loop, resulting in a denial of service. (CVE-2020-13935)
It was discovered that Tomcat did not properly deserialize untrusted da
Red Hat
tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
vendor_redhat·2020-07-15·CVSS 7.5
CVE-2020-13934 [HIGH] CWE-400 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
A flaw was found in Apache Tomcat, where an h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests are made, an OutOfMemoryException could occur, leading to a denial of service. The highest threat from this vulnerability is to system availability.
Statement: Red Hat Certificate System 10.0 and Red Hat Enterprise Linux 8's Identity Management, are u
Debian
CVE-2020-13934: tomcat9 - An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9....
vendor_debian·2020·CVSS 7.5
CVE-2020-13934 [HIGH] CVE-2020-13934: tomcat9 - An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9....
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 9.0.37-1)
bullseye: resolved (fixed in 9.0.37-1)
forky: resolved (fixed in 9.0.37-1)
sid: resolved (fixed in 9.0.37-1)
trixie: resolved (fixed in 9.0.37-1)
Apache
Apache tomcat: CVE-2020-13934
vendor_apache·CVSS 7.5
CVE-2020-13934 [HIGH] Apache tomcat: CVE-2020-13934
Apache tomcat: CVE-2020-13934
An h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service. This was fixed with commit 923d8345 . This issue was reported publicly via the Apache Tomcat Users mailing list on 22 June 2020 without reference to the potential for DoS. After further discussion to identify the steps necessary to reproduce the issue, the root cause of the issue and the associated DoS risks were identified by the Apache Tomcat Security Team on 26 June 2020. The issue was made public on 14 July 2020. Affects: 8.5.1 to 8.5.56 7 June 2020 Fixed in Apache Tomcat 8.5.56 Important: HTTP/2 DoS
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS [fedora-all]
bugzilla·2020-08-10·CVSS 7.5
CVE-2020-13934 [HIGH] CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS [fedora-all]
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
bugzilla·2020-07-15·CVSS 7.5
CVE-2020-13934 [HIGH] CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
CVE-2020-13934 tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS
A flaw was found in the Apache Tomcat, where an h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
It affects the version of Apache Tomcat 10.0.0-M1 to 10.0.0-M6, Apache Tomcat 9.0.0.M5 to 9.0.36, Apache Tomcat 8.5.1 to 8.5.56.
Upstream commits:
Tomcat 10.0: https://github.com/apache/tomcat/commit/c9167ae30f3b03b112f3d81772e3450b7d0e6a25
Tomcat 9.0: https://github.com/apache/tomcat/commit/172977f04a5215128f1e278a688983dcd230f399
Tomcat 8.5: https://github.com/apache/tomcat/commit/923d834500802a61779318911d7898bd85fc950e
Reference: http:/
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.htmlhttps://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb88e31b0ca9c29652ee4f962e%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ra072b1f786e7d139e86f1d1145572e0ff71cef38a96d9c6f5362aac8%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/07/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20200724-0003/https://usn.ubuntu.com/4596-1/https://www.debian.org/security/2020/dsa-4727https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.htmlhttps://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb88e31b0ca9c29652ee4f962e%40%3Cannounce.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/ra072b1f786e7d139e86f1d1145572e0ff71cef38a96d9c6f5362aac8%40%3Cdev.tomcat.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/07/msg00017.htmlhttps://security.netapp.com/advisory/ntap-20200724-0003/https://usn.ubuntu.com/4596-1/https://www.debian.org/security/2020/dsa-4727https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-07-14
Published