CVE-2024-54677
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
Does this matter?
Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.
Description
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- apache/tomcat · netapp/bootstrap os
- Source
- security@apache.org
References
- https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2nMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2024/12/17/5Mailing List
- http://www.openwall.com/lists/oss-security/2024/12/17/6Mailing List
- http://www.openwall.com/lists/oss-security/2024/12/18/1Mailing List
- https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html
- https://security.netapp.com/advisory/ntap-20250131-0006/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.