CVE-2020-13935

All FrameworksApache TomcatCWE-OtherCVE-2020-13935

CVE-2020-13935

State: PUBLISHED · Published: 2020-07-14 · Updated: 2024-08-04 · Assigner: apache
Description
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2020/13xxx/CVE-2020-13935.json