geronimo:geronimo-tomcat@1.0-M4 vulnerabilities

  • latest version

    1.1.1

  • first published

    18 years ago

  • latest version published

    18 years ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the geronimo:geronimo-tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Denial of Service (DoS)

geronimo:geronimo-tomcat is a server runtime that integrates the best open source projects to create Java/OSGi server runtimes that meet the needs of enterprise developers and system administrators.

Affected versions of this package are vulnerable to Denial of Service (DoS). It computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

How to fix Denial of Service (DoS)?

There is no fixed version for geronimo:geronimo-tomcat.

[0,)