CVE Vulnerabilities

CVE-2024-23672

Incomplete Cleanup

Published: Mar 13, 2024 | Modified: May 19, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io minimus.io echohq.com

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.

Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Tomcat Apache 8.5.0 (including) 8.5.99 (excluding)
Tomcat Apache 9.0.0 (including) 9.0.86 (excluding)
Tomcat Apache 10.1.0 (including) 10.1.19 (excluding)
Tomcat Apache 11.0.0-milestone1 (including) 11.0.0-milestone1 (including)
Tomcat Apache 11.0.0-milestone10 (including) 11.0.0-milestone10 (including)
Tomcat Apache 11.0.0-milestone11 (including) 11.0.0-milestone11 (including)
Tomcat Apache 11.0.0-milestone12 (including) 11.0.0-milestone12 (including)
Tomcat Apache 11.0.0-milestone13 (including) 11.0.0-milestone13 (including)
Tomcat Apache 11.0.0-milestone14 (including) 11.0.0-milestone14 (including)
Tomcat Apache 11.0.0-milestone15 (including) 11.0.0-milestone15 (including)
Tomcat Apache 11.0.0-milestone16 (including) 11.0.0-milestone16 (including)
Tomcat Apache 11.0.0-milestone2 (including) 11.0.0-milestone2 (including)
Tomcat Apache 11.0.0-milestone3 (including) 11.0.0-milestone3 (including)
Tomcat Apache 11.0.0-milestone4 (including) 11.0.0-milestone4 (including)
Tomcat Apache 11.0.0-milestone5 (including) 11.0.0-milestone5 (including)
Tomcat Apache 11.0.0-milestone6 (including) 11.0.0-milestone6 (including)
Tomcat Apache 11.0.0-milestone7 (including) 11.0.0-milestone7 (including)
Tomcat Apache 11.0.0-milestone8 (including) 11.0.0-milestone8 (including)
Tomcat Apache 11.0.0-milestone9 (including) 11.0.0-milestone9 (including)
Red Hat Enterprise Linux 8 RedHat tomcat-1:9.0.87-1.el8_10.1 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat tomcat-1:9.0.87-1.el8_8.2 *
Red Hat Enterprise Linux 9 RedHat tomcat-1:9.0.87-1.el9_4.1 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat tomcat-1:9.0.87-1.el9_2.1 *
Red Hat JBoss Web Server 5 RedHat tomcat *
Red Hat JBoss Web Server 5.8 on RHEL 7 RedHat jws5-tomcat-0:9.0.87-3.redhat_00003.1.el7jws *
Red Hat JBoss Web Server 5.8 on RHEL 8 RedHat jws5-tomcat-0:9.0.87-3.redhat_00003.1.el8jws *
Red Hat JBoss Web Server 5.8 on RHEL 9 RedHat jws5-tomcat-0:9.0.87-3.redhat_00003.1.el9jws *
Red Hat JBoss Web Server 6 RedHat tomcat *
Red Hat JBoss Web Server 6.0 on RHEL 8 RedHat jws6-tomcat-0:10.1.8-7.redhat_00014.1.el8jws *
Red Hat JBoss Web Server 6.0 on RHEL 9 RedHat jws6-tomcat-0:10.1.8-7.redhat_00014.1.el9jws *
Tomcat10 Ubuntu esm-apps/noble *
Tomcat10 Ubuntu mantic *
Tomcat10 Ubuntu noble *
Tomcat10 Ubuntu upstream *
Tomcat6 Ubuntu trusty/esm *
Tomcat7 Ubuntu trusty/esm *
Tomcat8 Ubuntu esm-apps/bionic *
Tomcat9 Ubuntu devel *
Tomcat9 Ubuntu esm-apps/bionic *
Tomcat9 Ubuntu esm-apps/focal *
Tomcat9 Ubuntu esm-apps/jammy *
Tomcat9 Ubuntu esm-apps/noble *
Tomcat9 Ubuntu focal *
Tomcat9 Ubuntu jammy *
Tomcat9 Ubuntu mantic *
Tomcat9 Ubuntu noble *
Tomcat9 Ubuntu oracular *
Tomcat9 Ubuntu plucky *

Potential Mitigations

References