Linux Distros Unpatched Vulnerability : CVE-2024-23672
Discription

image
The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue. (CVE-2024-23672) Note that Nessus relies on the presence of the package as reported by the…Read More

Back to Main

Subscribe for the latest news: