CVE-2024-23672
published 2024-03-13CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to…
PriorityP341medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
2.31%
81.6th percentile
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.19 | 10.1.19 |
| apache | tomcat | >= 8.5.0 < 8.5.99 | 8.5.99 |
| apache | tomcat | >= 9.0.0 < 9.0.86 | 9.0.86 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.18 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M16 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.98 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.85 | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
osv6.3MEDIUM
vendor_oracle7.5MEDIUM
vendor_apache6.3HIGH
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
OSV
tomcat9 vulnerabilities
osv·2024-11-13·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A
remote attacke
OSV
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
osv·2024-03-13
CVE-2024-23672 [MEDIUM] Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
OSV
CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
osv·2024-03-13·CVSS 6.3
CVE-2024-23672 [MEDIUM] CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
GHSA
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
ghsa·2024-03-13
CVE-2024-23672 [MEDIUM] CWE-459 Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-11-13·CVSS 4.3
CVE-2023-45648 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tom
Oracle
Oracle Oracle Communications Risk Matrix: CMP (Apache Tomcat) — CVE-2024-23672
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-23672 [MEDIUM] Oracle Oracle Communications Risk Matrix: CMP (Apache Tomcat) — CVE-2024-23672
Oracle Oracle Communications Risk Matrix: CMP (Apache Tomcat) vulnerability
CVE: CVE-2024-23672
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) — CVE-2024-23672
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-23672 [MEDIUM] Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) — CVE-2024-23672
Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) vulnerability
CVE: CVE-2024-23672
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
Tomcat: WebSocket DoS with incomplete closing handshake
vendor_redhat·2024-03-13·CVSS 6.3
CVE-2024-23672 [MEDIUM] CWE-459 Tomcat: WebSocket DoS with incomplete closing handshake
Tomcat: WebSocket DoS with incomplete closing handshake
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
A denial of service (DoS) vulnerability present in the Apache Tomcat package arises from an incomplete cleanup process. Specifically, WebSocket clients can perpetuate WebSocket connections without proper termination, thereby causing a sustained drain
Debian
CVE-2024-23672: tomcat10 - Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was ...
vendor_debian·2024·CVSS 6.3
CVE-2024-23672 [MEDIUM] CVE-2024-23672: tomcat10 - Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was ...
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u2)
forky: resolved (fixed in 10.1.20-1)
sid: resolved (fixed in 10.1.20-1)
trixie: resolved (fixed in 10.1.20-1)
Apache
Apache tomcat: CVE-2024-23672
vendor_apache·CVSS 6.3
CVE-2024-23672 [HIGH] Apache tomcat: CVE-2024-23672
Apache tomcat: CVE-2024-23672
It was possible for a WebSocket client to keep a WebSocket connection open leading to increased resource consumption. This was fixed with commit 3631adb1 . This issue was identified by the Tomcat Security Team on 17 January 2024. The issue was made public on 13 March 2024. Affects: 8.5.0 to 8.5.98 Important: Denial of Service
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2fhttp://www.openwall.com/lists/oss-security/2024/03/13/4https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2fhttps://lists.debian.org/debian-lts-announce/2024/04/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/https://lists.fedoraproject.org/archives/list/[email protected]/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/https://security.netapp.com/advisory/ntap-20240402-0002/
2024-03-13
Published