cbcvebase.
CVE-2024-54677
published 2024-12-17

CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects…

PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.95%
78.1th percentile
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

Affected

9 ranges
VendorProductVersion rangeFixed in
apachetomcat>= 10.1.0 < 10.1.3410.1.34
apachetomcat>= 11.0.0 < 11.0.211.0.2
apachetomcat>= 9.0.0 < 9.0.989.0.98
apache_software_foundationapache_tomcat10.1.0-M1 – 10.1.33
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.1
apache_software_foundationapache_tomcat8.5.0 – 8.5.100
apache_software_foundationapache_tomcat9.0.0.M1 – 9.0.97
debiantomcat10< tomcat10 10.1.34-0+deb12u1 (bookworm)tomcat10 10.1.34-0+deb12u1 (bookworm)
debiantomcat9< tomcat10 10.1.34-0+deb12u1 (bookworm)tomcat10 10.1.34-0+deb12u1 (bookworm)

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.