CVE-2020-13935

Description

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
92.155

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 10.0.0-M7Windows
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 9.0.37Windows
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 8.5.57Windows
Vulnerabilities CVE-2020-13935 are fixed in 7 July 2020 Fixed in Apache Tomcat 7.0.105Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat 10.0.0Windows
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat 9.0.37Windows
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat 8.5.57Windows
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat 7.0.105Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0.0Windows
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-admin-webapps-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-docs-webapp-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-el-3_0-api-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-javadoc-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-jsp-2_3-api-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-lib-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-servlet-4_0-api-9.0.36-3.45.1.noarch.rpmLinux
SUSE-SU-2020:2037-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-webapps-9.0.36-3.45.1.noarch.rpmLinux
Servlet and JSP engine (USN-4448-1) tomcat8_8.0.32-1ubuntu1.13_all.debLinux
Servlet and JSP engine (USN-4448-1) libtomcat8-java_8.0.32-1ubuntu1.13_all.debLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-admin-webapps-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-docs-webapp-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-el-2.2-api-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-javadoc-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-jsp-2.2-api-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-jsvc-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-lib-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-servlet-3.0-api-7.0.76-15.el7.noarch.rpmLinux
(RHSA-2020:4004) tomcat security and bug fix update tomcat-webapps-7.0.76-15.el7.noarch.rpmLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-4596-1) tomcat9_9.0.31-1ubuntu0.1_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-4596-1) tomcat9-common_9.0.31-1ubuntu0.1_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-4596-1) libtomcat9-java_9.0.31-1ubuntu0.1_all.debLinux
Apache Tomcat 9 - Servlet and JSP engine (USN-4596-1) libtomcat9-embed-java_9.0.31-1ubuntu0.1_all.debLinux
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 10.0.0-M7 (For Linux)Linux
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 9.0.37 (For Linux)Linux
Vulnerabilities CVE-2020-13935,CVE-2020-13934 are fixed in 5 July 2020 Fixed in Apache Tomcat 8.5.57 (For Linux)Linux
Vulnerabilities CVE-2020-13935 are fixed in 7 July 2020 Fixed in Apache Tomcat 7.0.105 (For Linux)Linux
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat for Linux 10.0.0Linux
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat for Linux 9.0.37Linux
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat for Linux 8.5.57Linux
Vulnerabilities CVE-2020-13935 are fixed in Apache - tomcat for Linux 7.0.105Linux
Loop with Unreachable Exit Condition (Infinite Loop) Vulnerability (CVE-2020-13935)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234