{"id":"GHSA-wf5v-jhxj-q632","summary":"Denial of service in Apache Tomcat","details":"java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a \"Content-Length: 0\" AJP request to trigger a hang in request processing.","aliases":["CVE-2014-0095"],"modified":"2024-11-28T05:36:07.555519Z","published":"2022-05-17T00:24:30Z","database_specific":{"nvd_published_at":"2014-05-31T11:17:00Z","cwe_ids":["CWE-20"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-08T20:19:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0095"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/8884dae60ace77a87ed9385442ce429e98c3a479"},{"type":"WEB","url":"https://github.com/apache/tomcat80/commit/77590c897f0e542fe363d70efdf3b82209510aee"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://web.archive.org/web/20140713043210/http://www.securitytracker.com/id/1030300"},{"type":"WEB","url":"https://web.archive.org/web/20141126170141/http://www.securityfocus.com/bid/67673"},{"type":"WEB","url":"https://web.archive.org/web/20151017043748/http://secunia.com/advisories/60729"},{"type":"WEB","url":"https://web.archive.org/web/20161024215453/http://secunia.com/advisories/59873"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2014/May/134"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1578392"},{"type":"WEB","url":"http://tomcat.apache.org/security-8.html"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21678231"},{"type":"WEB","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21681528"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html"}],"affected":[{"package":{"name":"org.apache.tomcat:tomcat-coyote","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat-coyote"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-RC1"},{"fixed":"8.0.4"}]}],"versions":["8.0.0-RC1","8.0.0-RC10","8.0.0-RC3","8.0.0-RC5","8.0.1","8.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wf5v-jhxj-q632/GHSA-wf5v-jhxj-q632.json"}},{"package":{"name":"org.apache.tomcat.embed:tomcat-embed-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0-RC1"},{"fixed":"8.0.4"}]}],"versions":["8.0.0-RC1","8.0.0-RC10","8.0.0-RC3","8.0.0-RC5","8.0.1","8.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wf5v-jhxj-q632/GHSA-wf5v-jhxj-q632.json"}}],"schema_version":"1.9.0"}