CVE-2024-38286
Vulnerability Summary
Timeline
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Metrics
- v4.0•HIGH•Score: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H
- v3.1•HIGH•Score: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.69%• Percentile: 76%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- apache software foundation•apache tomcat
≥ 11.0.0-M1, ≤ 11.0.0-M20 | ≥ 10.1.0-M1, ≤ 10.1.24 | ≥ 9.0.13, ≤ 9.0.89 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109
- apache•tomcat
≥ 9.0.13, < 9.0.90 | ≥ 10.1.1, < 10.1.25 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone15 | 10.1.0:milestone16 | 10.1.0:milestone17 | 10.1.0:milestone18 | 10.1.0:milestone19 | 10.1.0:milestone2 | 10.1.0:milestone20 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone12 | 11.0.0:milestone13 | 11.0.0:milestone14 | 11.0.0:milestone15 | 11.0.0:milestone16 | 11.0.0:milestone17 | 11.0.0:milestone18 | 11.0.0:milestone19 | 11.0.0:milestone2 | 11.0.0:milestone20 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9
- chainguard•tomcat-8.5.87
all | < 8.5.87-r6
- debian•tomcat10
< 10.1.34-0+deb12u1 | < 10.1.25-1 | < 10.1.25-1
- debian•tomcat9
< 9.0.43-2~deb11u11 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2
- org.apache.tomcat•tomcat-coyote
≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109
- org.apache.tomcat•tomcat-util
≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109
- org.apache.tomcat.embed•tomcat-embed-core
≥ 11.0.0-M1, < 11.0.0-M21 | ≥ 10.1.0-M1, < 10.1.25 | ≥ 9.0.13, < 9.0.90 | ≥ 8.5.35, ≤ 8.5.100 | ≥ 7.0.92, ≤ 7.0.109
- netapp•ontap_tools
9 | 10
- redhat•apache-commons-collections
< 0:3.2.2-10.module+el8.1.0+3366+6dfb954c
- redhat•apache-commons-lang
< 0:2.6-21.module+el8.1.0+3366+6dfb954c
- redhat•apache-commons-net
< 0:3.6-3.module+el8.3.0+6805+72837426
- redhat•bea-stax
< 0:1.2.0-16.module+el8.1.0+3366+6dfb954c
- redhat•bea-stax-api
< 0:1.2.0-16.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-fastinfoset
< 0:1.2.13-9.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-jaxb
< 0:2.2.11-11.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-jaxb-api
< 0:2.2.12-8.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-jaxb-core
< 0:2.2.11-11.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-jaxb-runtime
< 0:2.2.11-11.module+el8.1.0+3366+6dfb954c
- redhat•glassfish-jaxb-txw2
< 0:2.2.11-11.module+el8.1.0+3366+6dfb954c
- redhat•idm-pki-acme
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-base
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-base-java
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-ca
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-kra
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-server
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-symkey
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-symkey-debuginfo
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-tools
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•idm-pki-tools-debuginfo
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•jackson-annotations
< 0:2.10.0-1.module+el8.2.0+5059+3eb3af25
- redhat•jackson-core
< 0:2.10.0-1.module+el8.2.0+5059+3eb3af25
- redhat•jackson-databind
< 0:2.10.0-1.module+el8.2.0+5059+3eb3af25
- redhat•jackson-jaxrs-json-provider
< 0:2.9.9-1.module+el8.1.0+3832+9784644d
- redhat•jackson-jaxrs-providers
< 0:2.9.9-1.module+el8.1.0+3832+9784644d
- redhat•jackson-module-jaxb-annotations
< 0:2.7.6-4.module+el8.1.0+3366+6dfb954c
- redhat•jakarta-commons-httpclient
< 1:3.1-28.module+el8.1.0+3366+6dfb954c
- redhat•javassist
< 0:3.18.1-8.module+el8.1.0+3366+6dfb954c
- redhat•javassist-javadoc
< 0:3.18.1-8.module+el8.1.0+3366+6dfb954c
- redhat•jss
< 0:4.9.4-1.module+el8.7.0+15532+95bac9ee
- redhat•jss-debuginfo
< 0:4.9.4-1.module+el8.7.0+15532+95bac9ee
- redhat•jss-debugsource
< 0:4.9.4-1.module+el8.7.0+15532+95bac9ee
- redhat•jss-javadoc
< 0:4.9.4-1.module+el8.7.0+15532+95bac9ee
- redhat•ldapjdk
< 0:4.23.0-1.module+el8.5.0+11983+6ba118b4
- redhat•ldapjdk-javadoc
< 0:4.23.0-1.module+el8.5.0+11983+6ba118b4
- redhat•pki-core
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•pki-core-debuginfo
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•pki-core-debugsource
< 0:10.14.3-3.module+el8.8.0+22366+77f9de5e
- redhat•pki-servlet-4.0-api
< 1:9.0.50-1.el9_2.1 | < 1:9.0.30-1.module+el8.4.0+22383+8a8bb077.1 | < 1:9.0.43-4.el9_0.1 | < 1:9.0.7-16.module+el8.2.0+22384+93cade87.1 | < 1:9.0.30-3.module+el8.6.0+22385+e922a50e.1
- redhat•pki-servlet-engine
< 1:9.0.50-1.el9_2.1 | < 1:9.0.30-1.module+el8.4.0+22383+8a8bb077.1 | < 1:9.0.43-4.el9_0.1 | < 1:9.0.62-1.module+el8.8.0+22367+4894538d | < 1:9.0.7-16.module+el8.2.0+22384+93cade87.1 | < 1:9.0.30-3.module+el8.6.0+22385+e922a50e.1
Showing first 50 affected entries in server-rendered view.
References (28)
- https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
- http://www.openwall.com/lists/oss-security/2024/09/23/2
- https://security.netapp.com/advisory/ntap-20241101-0010/
- https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-38286
- https://github.com/apache/tomcat/commit/3197862639732e16ec1164557bcd289ebc116c93
- https://github.com/apache/tomcat/commit/3344c17cef094da4bb616f4186ed32039627b543
- https://github.com/apache/tomcat/commit/76c5cce6f0bcef14b0c21c38910371ca7d322d13
- https://github.com/apache/tomcat
- https://security.netapp.com/advisory/ntap-20241101-0010
- https://access.redhat.com/errata/RHSA-2024:8494
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2314686
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8494.json
- https://access.redhat.com/security/cve/CVE-2024-38286
- https://www.cve.org/CVERecord?id=CVE-2024-38286
- https://access.redhat.com/errata/RHSA-2024:8497
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8497.json
- https://access.redhat.com/errata/RHSA-2024:8528
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8528.json
- https://access.redhat.com/errata/RHSA-2024:8543
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8543.json
- https://access.redhat.com/errata/RHSA-2024:8567
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8567.json
- https://access.redhat.com/errata/RHSA-2024:8572
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_8572.json
- https://security-tracker.debian.org/tracker/CVE-2024-38286
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38286.json