CVE-2019-10072

Related Vulnerabilities: CVE-2019-10072  

Impact: Moderate Public Date: 2019-06-21 CWE: CWE-400 Bugzilla: 1723708: CVE-2019-10072 tomcat: HTTP/2 implementation leads to denial of service The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

The MITRE CVE dictionary describes this issue as:

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.

Find out more about CVE-2019-10072 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Impact None
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat JBoss Web Server 5 tomcat Affected
Red Hat JBoss Fuse 7 tomcat Affected
Red Hat JBoss Fuse 6 tomcat Affected
Red Hat JBoss Data Grid 7 tomcat Affected
Red Hat JBoss BRMS 6 tomcat Out of support scope
Red Hat JBoss BPMS 6 tomcat Out of support scope

External References