vendor:
Tomcat
by:
Cristian 'void' Giustini
7.5
CVSS
HIGH
Denial Of Service
400
CWE
Product Name: Tomcat
Affected Version From: 10
Affected Version To: 10.1
Patch Exists: YES
Related CWE: CVE-2022-29885
CPE: a:apache:tomcat:10.1
Platforms Tested: Windows, Linux, Mac
2022
Apache Tomcat 10.1 – Denial Of Service
A denial of service vulnerability exists in Apache Tomcat 10.1, which could allow an attacker to cause a denial of service condition. This vulnerability is due to an improper handling of requests in the cluster service. An attacker can exploit this vulnerability by sending a specially crafted request to the cluster service. Successful exploitation of this vulnerability could allow an attacker to cause a denial of service condition.
Mitigation:
To mitigate this vulnerability, users should upgrade to the latest version of Apache Tomcat 10.1. Additionally, users should ensure that the cluster service is properly configured and that all requests are properly handled.