CVE-2014-0230
Uncontrolled Resource Consumption in Apache Tomcat
EPSS 20.3%
描述
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
如何修補 CVE-2014-0230
要修補 CVE-2014-0230,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 6.0.44 或更新版本
CVE-2014-0230 正在被利用嗎?
中等 — EPSS 為 20.3%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 6.0.0, < 6.0.44