CVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service

CVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service-渗透云记 - 专注于网络安全与技术分享
CVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-13935: Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service

漏洞描述

Apache Tomcat versions 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56, and 7.0.27 to 7.0.104 contain a vulnerability in the WebSocket module where the payload length of WebSocket frames is not correctly validated. This can lead to an infinite loop when processing frames with invalid payload lengths. Attackers can exploit this flaw by sending multiple malicious requests, resulting in a denial of service (DoS) on the affected Tomcat instance.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享