Description
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
Remediation
References
Related Vulnerabilities
Open Resty Uncontrolled Resource Consumption Vulnerability (CVE-2023-44487)
Joomla CVE-2012-0836 Vulnerability (CVE-2012-0836)
WordPress Plugin Meta Slider and Carousel with Lightbox Cross-Site Request Forgery (1.6.2)
WordPress Plugin WF Cookie Consent Cross-Site Scripting (1.1.3)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-6131)