Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Apache Tomcat does not properly handle an invalid Transfer-Encoding header

GHSA-cxg2-49rq-8gcr · CVE-2010-2227

Published · Modified

Description

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes