Skip to content

CVE: 2023-44487 found in tomcat-embed-core - Version: 9.0.36 [GO] #161

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageGO
VulnerabilityDenial Of Service (DoS)
Vulnerability descriptionLibraries that implement HTTP/2 are vulnerable to Denial Of Service (DoS). The vulnerability could be exploited by attackers via sending a large number of HTTP/2 requests to a vulnerable server, then canceling them, causing the server to consume excessive resources and become unavailable to legitimate users. This vulnerability is known as "Rapid Reset".
CVE2023-44487
CVSS score7.8
Vulnerability present in version/s9.0.0.M1-9.0.80
Found library version/s9.0.36
Vulnerability fixed in version9.0.81
Library latest version11.0.9
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions