CVE-2017-5650 Details
Description
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | 8.5.0 8.5.1 8.5.2 8.5.3 8.5.4 8.5.5 8.5.6 8.5.7 8.5.8 8.5.9 8.5.10 8.5.11 8.5.12 9.0.0 milestone1 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone2 9.0.0 milestone3 9.0.0 milestone4 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 |
CPE
Remediation
| |
Change History
36 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Status Change | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Dec 8, 2023 | CPE Deprecation Remap | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Feb 13, 2020 | CVE Modified | [email protected] |
| Feb 3, 2020 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Apr 15, 2019 | CVE Modified | [email protected] |
| Mar 25, 2019 | CVE Modified | [email protected] |
| Mar 21, 2019 | CVE Modified | [email protected] |
| Jun 16, 2018 | CVE Modified | [email protected] |
| Aug 9, 2017 | CVE Modified | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| Jul 1, 2017 | CVE Modified | [email protected] |
| Apr 21, 2017 | Initial Analysis | [email protected] |
| Apr 19, 2017 | CVE Modified | [email protected] |