Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
A vulnerability allowing unbounded resource allocation has been identified in Apache Tomcat's WebDAV LOCK and PROPFIND request handling. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, and 9.0.0-M1 prior to 9.0.117. Older, unsupported versions may also be affected. The vulnerability arises because no limit was imposed on the request body for WebDAV LOCK or PROPFIND requests, which were accessible to unauthenticated users.
Exploitation of this vulnerability could lead to unbounded resource consumption, potentially causing a denial-of-service condition.
Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.