Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS01Y3c0LWdneDktMzZ2Z82_fQ

Apache Tomcat Denial of Service via Malformed Request Headers

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.

Permalink: https://github.com/advisories/GHSA-5cw4-ggx9-36vg
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS01Y3c0LWdneDktMzZ2Z82_fQ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 3 months ago


Identifiers: GHSA-5cw4-ggx9-36vg, CVE-2009-0033
References: Blast Radius: 0.0

Affected Packages

maven:org.apache.tomcat:tomcat
Dependent packages: 30
Dependent repositories: 438
Downloads:
Affected Version Ranges: >= 6.0.0, <= 6.0.18, >= 5.5.0, <= 5.5.27, >= 4.1.0, <= 4.1.39
No known fixed version
All affected versions: