VDB
BIT-tomcat-2020-13935
BIT-tomcat-2020-13935
PUBLISHED
CVSS 7.5 HIGH
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tomcat | 7.0.27, 8.5.0, 9.0.1 |
Exploit Intelligence
- aabbcc19191/CVE-2020-13935 (github-poc-repo)
- aabbcc19191/CVE-2020-13935 (github-poc)
- Exploit for WebSocket Vulnerability in Apache Tomcat (github-poc)
- dependency-check-suppression.xml (github-poc)
Timeline
- Mar 6, 2024 CVE Published
- Mar 20, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
References
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html url
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html url
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332 url
- https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E url
- https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html url
- https://security.netapp.com/advisory/ntap-20200724-0003/ url
- https://usn.ubuntu.com/4448-1/ url
- https://usn.ubuntu.com/4596-1/ url
- https://www.debian.org/security/2020/dsa-4727 url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://www.oracle.com/security-alerts/cpujan2022.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-13935 url