Description
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
Remediation
References
Related Vulnerabilities
Dot CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-37033)
WordPress Plugin WP Server Log Viewer Cross-Site Scripting (1.0)
WordPress Plugin One User Avatar-User Profile Picture Multiple Vulnerabilities (2.3.6)
MySQL Use After Free Vulnerability (CVE-2019-7317)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-16738)