Apache Tomcat does not properly handle an invalid Transfer-Encoding header
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Package
Affected versions
>= 7.0.0, < 7.0.2
>= 5.5.0, < 5.5.30
>= 6.0.0, < 6.0.28
Patched versions
7.0.2
5.5.30
6.0.28
Description
Published by the National Vulnerability Database
Jul 13, 2010
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 21, 2024
Last updated
Mar 1, 2024
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
References