VDB
BIT-tomcat-2020-13935
BIT-tomcat-2020-13935
PUBLISHED
CVSS 7.5 HIGH
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | tomcat | 7.0.27, 8.5.0, 9.0.1 |
Timeline
- Mar 6, 2024 CVE Published
- Mar 20, 2026 CVE Updated
- May 11, 2026 Distribution Patch
References
- https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E url
- https://security.netapp.com/advisory/ntap-20200724-0003/ url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://usn.ubuntu.com/4596-1/ url
- https://www.oracle.com/security-alerts/cpujan2021.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-13935 url
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html url
- https://www.oracle.com/security-alerts/cpuApr2021.html url
- https://www.oracle.com/security-alerts/cpuapr2022.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E url
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html url
- https://www.oracle.com/security-alerts/cpujan2022.html url
- https://usn.ubuntu.com/4448-1/ url
- https://kc.mcafee.com/corporate/index?page=content&id=SB10332 url
- https://www.debian.org/security/2020/dsa-4727 url
- https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html url
- https://www.oracle.com/security-alerts/cpuoct2020.html url