Back to search
CVE-2020-11996
Published: Jun 26, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
| Vendor | Product | Versions |
|---|---|---|
Apache | Apache Tomcat | affected 10.0.0-M1 to 10.0.0-M5affected 9.0.0.M1 to 9.0.35affected 8.5.0 to 8.5.55 |
References
[ofbiz-notifications] 20200628 [jira] [Created] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)
mailing-list
x_refsource_MLIST
[ofbiz-notifications] 20200628 [jira] [Closed] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)
mailing-list
x_refsource_MLIST
[ofbiz-notifications] 20200701 [jira] [Reopened] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)
mailing-list
x_refsource_MLIST
[ofbiz-notifications] 20200703 [jira] [Closed] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20200712 [SECURITY] [DLA 2279-1] tomcat8 security update
mailing-list
x_refsource_MLIST
DSA-4727
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2020:1051
vendor-advisory
x_refsource_SUSE
openSUSE-SU-2020:1063
vendor-advisory
x_refsource_SUSE
[tomcat-users] 20201008 Is Tomcat7 supports HTTP2
mailing-list
x_refsource_MLIST
https://www.oracle.com/security-alerts/cpuoct2020.html
x_refsource_MISC
https://security.netapp.com/advisory/ntap-20200709-0002/
x_refsource_CONFIRM
USN-4596-1
vendor-advisory
x_refsource_UBUNTU
https://www.oracle.com/security-alerts/cpujan2021.html
x_refsource_MISC
[ofbiz-notifications] 20210301 [jira] [Updated] (OFBIZ-11848) Upgrade Tomcat from 9.0.34 to 9.0.36 (CVE-2020-11996)
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now