Apache Tomcat DoS via Malicious Get Request
High severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Feb 12, 2024
Package
Affected versions
>= 4.0.0, <= 4.1.12
Patched versions
None
Description
Published by the National Vulnerability Database
Dec 31, 2002
Published to the GitHub Advisory Database
Apr 30, 2022
Reviewed
Feb 12, 2024
Last updated
Feb 12, 2024
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
References