CVE-2014-0227

EPSS 78.2%

Improper Input Validation in Apache Tomcat

發布日:2022/5/14修改日:2024/12/8

描述

`java/org/apache/coyote/http11/filters/ChunkedInputFilter.java` in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

受影響套件(2)

參考連結(33)