CVE-2020-13935
CVE-2020-13935 updated by NVD
Summary
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Maven | org.apache.tomcat.embed:tomcat-embed-websocket | — | 7.0.105, 8.5.57, 9.0.37, 10.0.0-M7 |
| Maven | org.apache.tomcat:tomcat | — | 10.0.0-M7, 9.0.37, 8.5.57, 7.0.105 |
| Maven | org.apache.tomcat:tomcat-websocket | — | 10.0.0-M7, 9.0.37, 8.5.57, 7.0.105 |
Remediation: Upgrade to 7.0.105 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.