5.3
MEDIUM
CVE-2024-54677
Apache Tomcat Uncontrolled Resource Consumption Denial of Service
Description

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.

INFO

Published Date :

Dec. 17, 2024, 1:15 p.m.

Last Modified :

Dec. 18, 2024, 5:15 p.m.

Remotely Exploitable :

Yes !

Impact Score :

1.4

Exploitability Score :

3.9
Affected Products

The following products are affected by CVE-2024-54677 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Apache tomcat
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2024-54677.

URL Resource
https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n
http://www.openwall.com/lists/oss-security/2024/12/17/5
http://www.openwall.com/lists/oss-security/2024/12/17/6
http://www.openwall.com/lists/oss-security/2024/12/18/1

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2024-54677 vulnerability anywhere in the article.

  • TheCyberThrone
CVE-2025-0107 PoC Exploit Code Released for PaloAlto Flaw

Background:CVE-2025-0107 is a critical OS command injection vulnerability discovered in Palo Alto Networks’ Expedition Tool, version 1.2.101 and earlier. Recently, security researchers released a Proo ... Read more

Published Date: Jan 19, 2025 (13 hours, 21 minutes ago)
  • TheCyberThrone
CVE-2024-44243: macOS SIP Bypass Flaw

CVE-2024-44243 is a critical vulnerability discovered in macOS that allows attackers to bypass Apple’s System Integrity Protection (SIP) by exploiting third-party kernel extensions. This vulnerability ... Read more

Published Date: Jan 15, 2025 (3 days, 21 hours ago)
  • TheCyberThrone
CISA adds Fortinet flaw CVE-2024-55591 to KEV Catalog

CVE-2024-55591 is a critical vulnerability affecting Fortinet’s FortiOS and FortiProxy devices. This vulnerability allows a remote attacker to bypass authentication mechanisms and gain super-admin pri ... Read more

Published Date: Jan 15, 2025 (4 days, 6 hours ago)
  • TheCyberThrone
CVE-2024-5594 impacts OpenVPN

CVE-2024-5594 is a critical vulnerability identified in OpenVPN versions prior to 2.6.11. This vulnerability stems from improper sanitization of PUSH_REPLY messages, which allows attackers to inject u ... Read more

Published Date: Jan 12, 2025 (1 week ago)
  • TheCyberThrone
CVE-2024-53704 impacts SonicWall

CVE-2024-53704 is a high-severity vulnerability impacting SonicWall’s SSLVPN authentication mechanism. This flaw, with a CVSS score of 8.2, allows remote attackers to bypass authentication and gain un ... Read more

Published Date: Jan 11, 2025 (1 week, 1 day ago)
  • TheCyberThrone
CISA KEV UPDATE Part I – January 2025

The US CISA has added 3  vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on the evidence of active exploitation.CVE-2024-41713: Mitel MiCollab Path Traversal VulnerabilityDe ... Read more

Published Date: Jan 08, 2025 (1 week, 4 days ago)
  • TheCyberThrone
TheCyberThrone Security Biweekly Review – December 28, 2024

Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the biweekly ending Saturday, December 28, 2024.Indian users are ta ... Read more

Published Date: Dec 30, 2024 (2 weeks, 6 days ago)
  • TheCyberThrone
CVE-2024-45387 Critical Bug in Apache Traffic Control

CVE-2024-45387 represents a significant security concern within the Traffic Ops component of Apache Traffic Control, specifically impacting versionsThe heart of this vulnerability is an SQL injection ... Read more

Published Date: Dec 25, 2024 (3 weeks, 3 days ago)
  • TheCyberThrone
Microsoft Patch Tuesday Year 2024 Analysis

In 2024, Microsoft’s Patch Tuesday updates played a critical role in addressing security vulnerabilities across various platforms. Throughout the year, a total of 1,000+ vulnerabilities were patched, ... Read more

Published Date: Dec 25, 2024 (3 weeks, 4 days ago)
  • TheCyberThrone
Zeroday Vulnerabilities Prevailed in 2024 Analysis-Part II

This is the continuation of Zeroday vulnerabilities in 2024. Let’s delve deeply into the continuation of  zero-day vulnerabilities of 2024, providing a comprehensive analysis.1. CVE-2023-46805: Authen ... Read more

Published Date: Dec 24, 2024 (3 weeks, 5 days ago)
  • TheCyberThrone
CISA adds Acclaim Flaw CVE-2021-44207 to KEV Catalog

The US CISA has added new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitationCVE-2021-44207: Acclaim Systems USAHERDS Use of Hard-Coded Credentials V ... Read more

Published Date: Dec 23, 2024 (3 weeks, 5 days ago)
  • TheCyberThrone
BeyondTrust SaaS Breach  Comprehensive Breakdown

Incident DiscoveryOn December 2, 2024, BeyondTrust identified a significant security breach during a forensics investigation. This discovery set off a series of urgent actions to mitigate the impact a ... Read more

Published Date: Dec 23, 2024 (3 weeks, 6 days ago)
  • Cybersecurity News
CVE-2024-56337: Apache Tomcat Patches Critical RCE Vulnerability

The Apache Software Foundation recently released a critical security update to address a remote code execution (RCE) vulnerability in Apache Tomcat, identified as CVE-2024-56337. This vulnerability af ... Read more

Published Date: Dec 23, 2024 (3 weeks, 6 days ago)
  • TheCyberThrone
Detailing Databricks Vulnerability CVE-2024-49194

A critical vulnerability has been identified that affects the Databricks JDBC Driver. This vulnerability allows for remote code execution (RCE) through a JNDI injection exploit using a malicious JDBC ... Read more

Published Date: Dec 21, 2024 (4 weeks, 1 day ago)
  • TheCyberThrone
Sophos fixes Triple Critical Vulnerabilities in its Firewall

Sophos released patches for three critical security vulnerabilities in their widely-used network security tool, Sophos Firewall that posed significant risks, including remote code execution and privil ... Read more

Published Date: Dec 20, 2024 (4 weeks, 1 day ago)
  • TheCyberThrone
CISA adds BeyondTrust CVE-2024-12356 to its KEV Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.CVE-2024-12356: Command Injection Vulnerability in BeyondTrust PRA and RSO ... Read more

Published Date: Dec 20, 2024 (4 weeks, 2 days ago)
  • TheCyberThrone
Fortinet fixes several vulnerabilities including CVE-2023-34990

Fortinet has released patches for vulnerabilities affecting its popular products, including FortiClient VPN, FortiManager, and FortiWLM. These flaws range from password exposure to remote code executi ... Read more

Published Date: Dec 19, 2024 (4 weeks, 2 days ago)
  • TheCyberThrone
Clop ransomware exploits Cleo Vulnerability in its attacks

The Clop ransomware gang has recently claimed responsibility for a series of sophisticated data theft attacks targeting Cleo, a prominent provider of managed file transfer software. These attacks expl ... Read more

Published Date: Dec 17, 2024 (1 month ago)
  • TheCyberThrone
TheCyberThrone Security BiWeekly Review – December 14, 2024

Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the weeks ending Saturday, November 30, 2024.Jenkins fixes multiple ... Read more

Published Date: Dec 15, 2024 (1 month ago)
  • TheCyberThrone
CISA adds Cleo Vulnerability CVE-2024-50623 to KEV Catalog

The US CISA adds Cleo vulnerability to its Known Exploited Vulnerabilities Catalog based on the evidence of active exploitation reported.Security vendor Huntress was the first to publicize the attacks ... Read more

Published Date: Dec 14, 2024 (1 month ago)
  • TheCyberThrone
Gitlab fixes CVE-2024-11274 and CVE-2024-8233

GitLab has released a crucial security update to address multiple vulnerabilities impacting various versions of its platform. This update, applicable to versions 17.6.2, 17.5.4, and 17.4.6 for both Co ... Read more

Published Date: Dec 13, 2024 (1 month ago)
  • TheCyberThrone
Apache Struts was affected by CVE-2024-53677

Apache Struts framework has been detected with a critical vulnerability that could allow attackers to execute malicious code remotely, posing a significant risk to affected systems.The vulnerability t ... Read more

Published Date: Dec 13, 2024 (1 month ago)
  • TheCyberThrone
Splunk addresses CVE-2024-53247 in Secure Gateway

A critical vulnerability identified has been discovered in the Splunk Secure Gateway app, affecting various versions of Splunk Enterprise and the Splunk Cloud Platform.The vulnerability tracked as CVE ... Read more

Published Date: Dec 12, 2024 (1 month, 1 week ago)
  • TheCyberThrone
AuthQuake vulnerability with Microsoft to Bypass MFA

Cybersecurity researchers at Oasis Security have discovered a significant vulnerability in Microsoft’s Multi-Factor Authentication (MFA) system, which they have named AuthQuake.This vulnerability allo ... Read more

Published Date: Dec 12, 2024 (1 month, 1 week ago)
  • TheCyberThrone
Apache Superset 4.1.0 released with bug fixes

The Apache Software Foundation has announced the release of Apache Superset 4.1.0 with several bug fixes that could potentially allow attackers to bypass security controls, access sensitive data, and ... Read more

Published Date: Dec 11, 2024 (1 month, 1 week ago)
  • TheCyberThrone
Google fixes important vulnerabilities with the latest Google Chrome

Google has released updates for its Chrome browser, addressing several security vulnerabilities, including two important vulnerabilities.The first vulnerability tracked as CVE-2024-12381 with a CVSSv3 ... Read more

Published Date: Dec 11, 2024 (1 month, 1 week ago)
  • TheCyberThrone
CISA adds CVE-2024-49138 to its KEV Catalog

The US CISA adds Microsoft vulnerability to its Known Exploited Vulnerabilities Catalog based on the evidence of active exploitation.The vulnerability tracked as CVE-2024-49138 with a CVSS score of 7. ... Read more

Published Date: Dec 11, 2024 (1 month, 1 week ago)
  • TheCyberThrone
Exploit Code Released for Microsoft CVE-2024-38193

A critical use-after-free vulnerability, tracked as CVE-2024-38193 with a CVSS score of 7.8, has been discovered in the afd.sys Windows driver that allows attackers to escalate privileges and execute ... Read more

Published Date: Dec 09, 2024 (1 month, 1 week ago)
  • TheCyberThrone
Django was affected by CVE-2024-53907 and CVE-2024-53908

The Django team has released Django 5.1.4, Django 5.0.10, and Django 4.2.17 versions to address two security vulnerabilities.The first vulnerability tracked as CVE-2024-53907 with a CVSS score of 7.5 ... Read more

Published Date: Dec 08, 2024 (1 month, 1 week ago)
  • TheCyberThrone
SonicWall addressed half a dozen vulnerabilities in SMA 100 series

SonicWall has released patches for several (six) vulnerabilities impacting its SMA 100 series SSL-VPN products. These flaws range from path traversal issues inherited from the Apache HTTP Server to cr ... Read more

Published Date: Dec 07, 2024 (1 month, 1 week ago)
  • TheCyberThrone
SailPoint IdentityIQ affected by CVE-2024-10905

SailPoint IdentityIQ has been affected by a critical vulnerability, that could allow sensitive data exposureThe vulnerability tracked as CVE-2024-10905 with a CVSS score of 10.0, stems from improper a ... Read more

Published Date: Dec 05, 2024 (1 month, 2 weeks ago)
  • TheCyberThrone
CISA Adds CyberPanel Flaw CVE-2024-51378 to KEV Catalog

The CISA has warned about a critical vulnerability in CyberPanel tracked as CVE-2024-51378, is being actively exploited by attackers to deploy ransomware and added to the known exploited vulnerability ... Read more

Published Date: Dec 05, 2024 (1 month, 2 weeks ago)
  • TheCyberThrone
POC Exploit released for WhatsUp Gold CVE-2024-8785

Security researchers have published a proof-of-concept (PoC) exploit for CVE-2024-8785 with a CVSS score of 9.8, a critical remote code execution vulnerability affecting Progress WhatsUp Gold,A critic ... Read more

Published Date: Dec 05, 2024 (1 month, 2 weeks ago)
  • TheCyberThrone
Google Patches CVE-2024-12053 in Chrome

Google has released patches for a high severity vulnerability in its popular  Chrome web browser residing within the V8 JavaScript engine and allow attackers to execute arbitrary code on users’ system ... Read more

Published Date: Dec 04, 2024 (1 month, 2 weeks ago)
  • TheCyberThrone
CISA KEV Catalog Update Part I – December 2024

The US CISA has added the below vulnerabilities to its Known Exploited Vulnerabilities Catalog based on the evidence of active exploitation.CVE-2023-45727 Tracked as CWE-611, North Grid Proself Enterp ... Read more

Published Date: Dec 04, 2024 (1 month, 2 weeks ago)
  • TheCyberThrone
IBM fixes multiple vulnerabilities including CVE-2024-49803

IBM has  released patches for multiple vulnerabilities, that could lead to a remote code execution to hard-coded credentials and privilege escalation that potentially compromising sensitive data and d ... Read more

Published Date: Dec 03, 2024 (1 month, 2 weeks ago)

The following table lists the changes that have been made to the CVE-2024-54677 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Dec. 18, 2024

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2024/12/18/1
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Dec. 17, 2024

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2024/12/17/6
  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Dec. 17, 2024

    Action Type Old Value New Value
    Added Reference http://www.openwall.com/lists/oss-security/2024/12/17/5
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Dec. 17, 2024

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • New CVE Received by [email protected]

    Dec. 17, 2024

    Action Type Old Value New Value
    Added Description Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. Users are recommended to upgrade to version 11.0.2, 10.1.34 or 9.0.98, which fixes the issue.
    Added CWE CWE-400
    Added Reference https://lists.apache.org/thread/tdtbbxpg5trdwc2wnopcth9ccvdftq2n
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2024-54677 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2024-54677 weaknesses.

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability