Improper Input Validation Affecting tomcat package, versions [8.5.0,8.5.64)[9.0.0,9.0.44)[10.0.0,10.0.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.55% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TOMCAT-2382386
  • published26 Jan 2022
  • disclosed16 Sept 2021
  • creditUnknown

Introduced: 16 Sep 2021

CVE-2021-41079  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade tomcat to version 8.5.64, 9.0.44, 10.0.3 or higher.

Overview

Affected versions of this package are vulnerable to Improper Input Validation. Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.

CVSS Scores

version 3.1