CVE-2024-34750
published 2024-07-03CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.60%
90.6th percentile
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.25 | 10.1.25 |
| apache | tomcat | >= 9.0.0 < 9.0.90 | 9.0.90 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.24 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M20 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.89 | — |
| atlassian | crowd | — | — |
| debian | tomcat10 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| netapp | ontap_tools | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Oracle
Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) — CVE-2024-34750
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-34750 [HIGH] Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) — CVE-2024-34750
Oracle Oracle Communications Risk Matrix: Patches (Apache Tomcat) vulnerability
CVE: CVE-2024-34750
CVSS: 7.5
Protocol: HTTP/2
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Atlassian
CVE-2024-34750: DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency in Crowd Data Center and Server
vendor_atlassian·2024-11-19·CVSS 7.5
CVE-2024-34750 [HIGH] CVE-2024-34750: DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency in Crowd Data Center and Server
CVE-2024-34750: DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency in Crowd Data Center and Server
DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency in Crowd Data Center and Server
CVE: CVE-2024-34750
Affected products: Crowd
Oracle
Oracle Oracle Commerce Risk Matrix: Experience Manager (Apache Tomcat) — CVE-2024-34750
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-34750 [HIGH] Oracle Oracle Commerce Risk Matrix: Experience Manager (Apache Tomcat) — CVE-2024-34750
Oracle Oracle Commerce Risk Matrix: Experience Manager (Apache Tomcat) vulnerability
CVE: CVE-2024-34750
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
tomcat: Improper Handling of Exceptional Conditions
vendor_redhat·2024-07-03·CVSS 7.5
CVE-2024-34750 [HIGH] CWE-400 tomcat: Improper Handling of Exceptional Conditions
tomcat: Improper Handling of Exceptional Conditions
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.
Debian
CVE-2024-34750: tomcat10 - Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption v...
vendor_debian·2024·CVSS 7.5
CVE-2024-34750 [HIGH] CVE-2024-34750: tomcat10 - Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption v...
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
Scope: local
b
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
OSV
Apache Tomcat - Denial of Service
osv·2024-07-03
CVE-2024-34750 [HIGH] Apache Tomcat - Denial of Service
Apache Tomcat - Denial of Service
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
OSV
CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat
osv·2024-07-03·CVSS 7.5
CVE-2024-34750 [HIGH] CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
GHSA
Apache Tomcat - Denial of Service
ghsa·2024-07-03
CVE-2024-34750 [HIGH] CWE-400 Apache Tomcat - Denial of Service
Apache Tomcat - Denial of Service
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
No detection rules found.
No public exploits indexed.
2024-07-03
Published