BIT-tomcat-2020-13935

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2020-13935.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-tomcat-2020-13935
Aliases
Published
2024-03-06T11:11:44.067Z
Modified
2026-03-20T10:02:06.878435Z
Summary
[none]
Details

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.0.27
Fixed
7.0.105
Introduced
8.5.0
Fixed
8.5.57
Introduced
9.0.1
Fixed
9.0.37

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2020-13935.json"