CVE-2021-41079
🟡 Monitoruj
Błąd w Apache Tomcat prowadzi do odmowy usługi przez nieskończoną pętlę w TLS.
CVSS
7.5
EPSS
7.2%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 7.2% |
| Opublikowano (NVD) | 2021-09-16 15:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:12 UTC |
Referencje
- https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3E ([email protected])
- https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E ([email protected]) [Mailing List, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2021/09/msg00012.html ([email protected]) [Mailing List, Third Party Advisory]
- https://security.netapp.com/advisory/ntap-20211008-0005/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2021/dsa-4986 ([email protected]) [Third Party Advisory]