{"schema_version":"1.7.5","id":"GHSA-653p-vg55-5652","published":"2024-12-17T15:31:43Z","modified":"2026-07-06T14:30:08.890537747Z","aliases":["BIT-tomcat-2024-54677","CVE-2024-54677"],"summary":"Apache Tomcat Uncontrolled Resource Consumption vulnerability","details":"Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.\n\nUsers are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.\n\nThis vulnerability does not affect core Apache Tomcat server components (tomcat-catalina, tomcat-coyote, tomcat-embed-core, etc.). Removing the `webapps/examples/` directory in production environments — as recommended by the [Apache Tomcat Security Considerations documentation](https://tomcat.apache.org/tomcat-9.0-doc/security-howto.html#Examples) — eliminates the attack surface entirely.","affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"11.0.0-M1"},{"fixed":"11.0.2"}]}],"versions":["11.0.0","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M9","11.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0-M1"},{"fixed":"10.1.34"}]}],"versions":["10.1.0","10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M2","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.1","10.1.10","10.1.11","10.1.12","10.1.13","10.1.14","10.1.15","10.1.16","10.1.17","10.1.18","10.1.19","10.1.2","10.1.20","10.1.23","10.1.24","10.1.25","10.1.26","10.1.28","10.1.29","10.1.30","10.1.31","10.1.33","10.1.4","10.1.5","10.1.6","10.1.7","10.1.8","10.1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json"}},{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0.M1"},{"fixed":"9.0.98"}]}],"versions":["9.0.0.M1","9.0.0.M10","9.0.0.M11","9.0.0.M13","9.0.0.M15","9.0.0.M17","9.0.0.M18","9.0.0.M19","9.0.0.M20","9.0.0.M21","9.0.0.M22","9.0.0.M25","9.0.0.M26","9.0.0.M27","9.0.0.M3","9.0.0.M4","9.0.0.M6","9.0.0.M8","9.0.0.M9","9.0.1","9.0.10","9.0.11","9.0.12","9.0.13","9.0.14","9.0.16","9.0.17","9.0.19","9.0.2","9.0.20","9.0.21","9.0.22","9.0.24","9.0.26","9.0.27","9.0.29","9.0.30","9.0.31","9.0.33","9.0.34","9.0.35","9.0.36","9.0.37","9.0.38","9.0.39","9.0.4","9.0.40","9.0.41","9.0.43","9.0.44","9.0.45","9.0.46","9.0.48","9.0.5","9.0.50","9.0.52","9.0.53","9.0.54","9.0.55","9.0.56","9.0.58","9.0.59","9.0.6","9.0.60","9.0.62","9.0.63","9.0.64","9.0.65","9.0.67","9.0.68","9.0.69","9.0.7","9.0.70","9.0.71","9.0.72","9.0.73","9.0.74","9.0.75","9.0.76","9.0.78","9.0.79","9.0.8","9.0.80","9.0.81","9.0.82","9.0.83","9.0.84","9.0.85","9.0.86","9.0.87","9.0.88","9.0.89","9.0.90","9.0.91","9.0.93","9.0.94","9.0.95","9.0.96","9.0.97"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-653p-vg55-5652/GHSA-653p-vg55-5652.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-54677"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/f57a9d9847c1038be61f5818d73b8be907c460d4"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/e8c16cdba833884e1bd49fff1f1cb699da177585"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/dbec927859d9484cb8bd680a7c67b1a560f48444"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/d63a10afc142b12f462a15f7d10f79fd80ff94eb"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/cb1707685472994e9d924746f8c91cb116fa5213"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/c2f7ce21c3fb12caefee87c517a8bb4f80700044"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/c0a23927ea5e061ca3fdff695138464179fe674a"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/bbd82e9593314ade4cfd57248f9285fbad686f66"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/aa5b4d0043289cf054f531ec55126c980d3572e1"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/a95bf2b0303442a2c9a1ac364b0e63b56049e33a"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/9ffd23fc27f5d1fc95bf97e5cea175c8968f4533"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/84c4af76e7a10fc7f8630ce62e6a46632ea4a90e"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/84065e26ca4555e63a922bb29b13b0a1c86b7654"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/75ff7e8622edcc024b268677aa789ee8f0880ecc"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/722814668708c42a61b0c1e340b15bc2b785c0d1"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/721544ea28e92549824b106be954a9f411867a1c"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/54e56495e9a106218efe9fc9c79d976c0032bbfd"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/4f0236606961176257b883213e1621b1859ed746"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/4d5cc6538d91386f950373ac8120e98c2c78ed3a"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/4a335c6dcba8d6f8a54629eda392a50da267bdf4"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/3315a9027a7eaab18f42625b97b569940ff1365d"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/1d88dd3ffaed76188dd4ee32ce77709ce6e153cd"},{"type":"WEB","url":"https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.34"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20250131-0006"},{"type":"WEB","url":"https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2"},{"type":"WEB","url":"https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.98"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html"},{"type":"WEB","url":"https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/12/17/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/12/17/6"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/12/18/1"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2024-12-17T16:41:30Z","nvd_published_at":"2024-12-17T13:15:18Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}