Apache Tomcat March Vulnerability Security Update Advisory

Overview

 

Apache Tomcat(https://tomcat.apache.org/) has released a security update that addresses a vulnerability in its shipped products. users of affected products are advised to update to the latest version.

 

Affected Products

 

Apache Tomcat 9.0.0-M1 – 9.0.85

Apache Tomcat 8.5.0 – 8.5.98

Apache Tomcat 11.0.0-M1 – 11.0.0-M16

Apache Tomcat 10.1.0-M1 – 10.1.18

 

Resolved Vulnerabilities

 

Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2024-24549)

Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2024-23672)

 

Vulnerability Patches

 

Please follow the security advisory published on March 13, 2024 to update to the appropriate version and the latest version.

Apache Tomcat 9.0.86

Apache Tomcat 8.5.99

Apache Tomcat 11.0.0-M17

Apache Tomcat 10.1.19

 

Referenced Sites

 

[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23672

[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24549

[3] https://tomcat.apache.org/security