--- vuln2.xml Fri Jun 26 08:39:11 2020 +++ vuln.xml Fri Jun 26 08:39:29 2020 @@ -60,0 +61,38 @@ + + Apache Tomcat -- HTTP/2 DoS + + + tomcat85 + 8.5.55 + + + tomcat9 + 9.0.36 + + + tomcat-devel + 10.0.0-M6 + + + + +

The Apache Software Foundation reports:

+
+

CVE-2020-11996: A specially crafted sequence of HTTP/2 requests could trigger high CPU +usage for several seconds. If a sufficient number of such requests were +made on concurrent HTTP/2 connections, the server could become unresponsive.

+
+ +
+ + http://tomcat.apache.org/security-8.html + http://tomcat.apache.org/security-9.html + http://tomcat.apache.org/security-10.html + CVE-2020-11996 + + + 2020-06-07 + 2020-06-26 + +
+