CVE-2024-54677
published 2024-12-17CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.95%
78.1th percentile
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.34 | 10.1.34 |
| apache | tomcat | >= 11.0.0 < 11.0.2 | 11.0.2 |
| apache | tomcat | >= 9.0.0 < 9.0.98 | 9.0.98 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.33 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.1 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.97 | — |
| debian | tomcat10 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat10 vulnerabilities
osv·2025-08-20·CVSS 9.8
CVE-2025-46701 [CRITICAL] tomcat10 vulnerabilities
tomcat10 vulnerabilities
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could possibly use this
issue to cause a denial of service. This i
OSV
Apache Tomcat Uncontrolled Resource Consumption vulnerability
osv·2024-12-17
CVE-2024-54677 [MEDIUM] Apache Tomcat Uncontrolled Resource Consumption vulnerability
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
GHSA
Apache Tomcat Uncontrolled Resource Consumption vulnerability
ghsa·2024-12-17
CVE-2024-54677 [MEDIUM] CWE-400 Apache Tomcat Uncontrolled Resource Consumption vulnerability
Apache Tomcat Uncontrolled Resource Consumption vulnerability
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
OSV
CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service
osv·2024-12-17·CVSS 5.3
CVE-2024-54677 [MEDIUM] CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-08-20·CVSS 9.8
CVE-2024-50379 [CRITICAL] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could
Red Hat
tomcat: Apache Tomcat: DoS in examples web application
vendor_redhat·2024-12-17·CVSS 5.3
CVE-2024-54677 [MEDIUM] CWE-400 tomcat: Apache Tomcat: DoS in examples web application
tomcat: Apache Tomcat: DoS in examples web application
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
A flaw was found in the "examples" web application of Apache Tomcat. Numerous examples within that application did not place limits on uploaded data. This vulnerability can potentially trigger an out-of-memory (OOM) error
Debian
CVE-2024-54677: tomcat10 - Uncontrolled Resource Consumption vulnerability in the examples web application ...
vendor_debian·2024·CVSS 5.3
CVE-2024-54677 [MEDIUM] CVE-2024-54677: tomcat10 - Uncontrolled Resource Consumption vulnerability in the examples web application ...
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 10.1.34-0+deb12u1)
forky: resolved (fixed in 10.1.34-1)
sid: resolved (fixed in 10.1.34-1)
trixie: resolved (fixed in 10.1.34-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2nhttp://www.openwall.com/lists/oss-security/2024/12/17/5http://www.openwall.com/lists/oss-security/2024/12/17/6http://www.openwall.com/lists/oss-security/2024/12/18/1https://lists.debian.org/debian-lts-announce/2025/07/msg00009.htmlhttps://security.netapp.com/advisory/ntap-20250131-0006/
2024-12-17
Published