Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Improper Input Validation in Apache Tomcat

GHSA-42j3-498q-m6vp · CVE-2014-0227

Published · Modified

Description

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes