Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2024:1204-1 — tomcat10 (CVE-2024-24549 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for tomcat10

This update for tomcat10 fixes the following issues:

  • CVE-2024-24549: Fixed denial of service during header validation for HTTP/2 stream (bsc#1221386)
  • CVE-2024-23672: Fixed denial of service due to malicious WebSocket client keeping connection open (bsc#1221385)

Other fixes:

  • Update to Tomcat 10.1.20
  • Catalina

+ Fix: Minor performance improvement for building filter chains.

Based on ideas from #702 by Luke Miao. (remm)

+ Fix: Align error handling for Writer and OutputStream. Ensure

use of either once the response has been recycled triggers a

NullPointerException provided that discardFacades is configured with

the default value of true. (markt)

+ Fix: 68692: The standard thread pool implementations that are

configured using the Executor element now implement ExecutorService

for better support NIO2. (remm)

+ Fix: 68495: When restoring a saved POST request after a

successful FORM authentication, ensure that neither the URI, the

query string nor the protocol are corrupted when restoring the

request body. (markt)

+ Fix: After forwarding a request, attempt to unwrap the

response in order to suspend it, instead of simply closing it if it

was wrapped. Add a new suspendWrappedResponseAfterForward boolean

attribute on Context to control the bahavior, defaulting to false.

(remm)

+ Fix: 68721: Workaround a possible cause of duplicate class

definitions when using ClassFileTransformers and the transformation

of a class also triggers the loading of the same class. (markt)

+ Fix: The rewrite valve should not do a rewrite if the output

is identical to the input. (remm)

+ Update: Add a new valveSkip (or VS) rule flag to the rewrite

valve to allow skipping over the next valve in the Catalina pipeline.

(remm)

+ Update: Add highConcurrencyStatus attribute to the

SemaphoreValve to optionally allow the valve to return an error

status code to the client when a permit cannot be acquired from the

semaphore. (remm)

+ Add: Add checking of the 'age' of the running Tomcat instance

since its build-date to the SecurityListener, and log a warning if

the server is old. (schultz)

+ Fix: When using the AsyncContext, throw an

IllegalStateException, rather than allowing an NullPointerException,

if an attempt is made to use the AsyncContext after it has been

recycled. (markt)

+ Fix: Correct JPMS and OSGi meta-data for tomcat-embed-core.jar

by removing reference to org.apache.catalina.ssi package that is no

longer included in the JAR. Based on pull request #684 by Jendrik

Johannes. (markt)

+ Fix: Fix ServiceBindingPropertySource so that trailing \r\n

sequences are correctly removed from files containing property values

when configured to do so. Bug identified by Coverity Scan. (markt)

+ Add: Add improvements to the CSRF prevention filter including

the ability to skip adding nonces for resource name and subtree URL

patterns. (schultz)

+ Fix: Review usage of debug logging and downgrade trace or data

dumping operations from debug level to trace. (remm)

+ Fix: 68089: Further improve the performance of request

attribute access for ApplicationHttpRequest and ApplicationRequest.

(markt)

+ Fix: 68559: Allow asynchronous error handling to write to the

response after an error during asynchronous processing. (markt)

  • Coyote

+ Fix: Improve the HTTP/2 stream prioritisation process. If a

stream uses all of the connection windows and still has content to

write, it will now be added to the backlog immediately rather than

waiting until the write attempt for the remaining content. (markt)

+ Fix: Add threadsMaxIdleTime attribute to the endpoint, to

allow configuring the amount of time before an internal executor will

scale back to the configured minSpareThreads size. (remm)

+ Fix: Correct a regression in the support for user provided

SSLContext instances that broke the

org.apache.catalina.security.TLSCertificateReloadListener. (markt)

+ Fix: Setting a null value for a cookie attribute should remove

the attribute. (markt)

+ Fix: Make asynchronous error handling more robust. Ensure that

once a connection is marked to be closed, further asynchronous

processing cannot change that. (markt)

+ Fix: Make asynchronous error handling more robust. Ensure that

once the call to AsyncListener.onError() has returned to the

container, only container threads can access the AsyncContext. This

protects against various race conditions that woudl otherwise occur

if application threads continued to access the AsyncContext.

+ Fix: Review usage of debug logging and downgrade trac

Affected software

SUSE-SU-2024:1204-1 is recorded against 1 package.

  • tomcat10 (fixed in 10.1.20-150200.5.22.2)

Timeline and source

Published on 11 April 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-04-11
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
tomcat10 10.1.20-150200.5.22.2

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:1204-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:1204-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.