Bug 1221385 (CVE-2024-23672) - VUL-0: CVE-2024-23672: tomcat,tomcat10: WebSocket DoS with incomplete closing handshake
Summary: VUL-0: CVE-2024-23672: tomcat,tomcat10: WebSocket DoS with incomplete closing...
Status: IN_PROGRESS
Alias: CVE-2024-23672
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Major
Target Milestone: ---
Assignee: Michele Bussolotto
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/397453/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-23672:7.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-03-14 09:48 UTC by SMASH SMASH
Modified: 2024-07-17 10:16 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
camila.matos: needinfo? (michele.bussolotto)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-03-14 09:48:58 UTC
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.

Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-23672
https://www.cve.org/CVERecord?id=CVE-2024-23672
https://seclists.org/oss-sec/2024/q1/226
https://lists.apache.org/thread/cmpswfx6tj4s7x0nxxosvfqs11lvdx2f
Comment 5 Maintenance Automation 2024-04-11 12:30:07 UTC
SUSE-SU-2024:1205-1: An update that solves two vulnerabilities can now be installed.

Category: security (important)
Bug References: 1221385, 1221386
CVE References: CVE-2024-23672, CVE-2024-24549
Maintenance Incident: [SUSE:Maintenance:33319](https://smelt.suse.de/incident/33319/)
Sources used:
SUSE Linux Enterprise High Performance Computing 12 SP5 (src):
 tomcat-9.0.36-3.124.1
SUSE Linux Enterprise Server 12 SP5 (src):
 tomcat-9.0.36-3.124.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src):
 tomcat-9.0.36-3.124.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Maintenance Automation 2024-04-11 12:30:09 UTC
SUSE-SU-2024:1204-1: An update that solves two vulnerabilities can now be installed.

Category: security (important)
Bug References: 1221385, 1221386
CVE References: CVE-2024-23672, CVE-2024-24549
Maintenance Incident: [SUSE:Maintenance:33312](https://smelt.suse.de/incident/33312/)
Sources used:
openSUSE Leap 15.5 (src):
 tomcat10-10.1.20-150200.5.22.2
Web and Scripting Module 15-SP5 (src):
 tomcat10-10.1.20-150200.5.22.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Maintenance Automation 2024-04-18 20:30:01 UTC
SUSE-SU-2024:1345-1: An update that solves two vulnerabilities can now be installed.

Category: security (important)
Bug References: 1221385, 1221386
CVE References: CVE-2024-23672, CVE-2024-24549
Maintenance Incident: [SUSE:Maintenance:33133](https://smelt.suse.de/incident/33133/)
Sources used:
openSUSE Leap 15.5 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
Development Tools Module 15-SP5 (src):
 geronimo-specs-1.2-150200.15.8.1
SUSE Package Hub 15 15-SP5 (src):
 geronimo-specs-1.2-150200.15.8.1
SUSE Manager Server 4.3 Module 4.3 (src):
 geronimo-specs-1.2-150200.15.8.1
Web and Scripting Module 15-SP5 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (src):
 geronimo-specs-1.2-150200.15.8.1
SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Manager Server 4.3 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1
SUSE Enterprise Storage 7.1 (src):
 apache-commons-pool2-2.4.2-150200.11.8.1, apache-commons-daemon-1.3.4-150200.11.14.1, geronimo-specs-1.2-150200.15.8.1, apache-commons-dbcp-2.1.1-150200.10.8.1, tomcat-9.0.87-150200.65.1, jakarta-taglibs-standard-1.1.1-150000.4.10.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Michele Bussolotto 2024-04-19 07:24:53 UTC
The SR for SUSE:ALP:Source:Standard:1.0 are here
https://build.suse.de/request/show/325915
https://build.suse.de/request/show/325916

but they're not accepted yet.

@fstrba
Are the SR ok or should I create them for src.suse.de ? Is there any guide for this new mechanism (in particular when we're doing a sync with factory) ?

Thanks
Comment 10 Fridrich Strba 2024-04-19 13:34:38 UTC
(In reply to Michele Bussolotto from comment #9)
> The SR for SUSE:ALP:Source:Standard:1.0 are here
> https://build.suse.de/request/show/325915
> https://build.suse.de/request/show/325916
> 
> but they're not accepted yet.
> 
> @fstrba
> Are the SR ok or should I create them for src.suse.de ? Is there any guide
> for this new mechanism (in particular when we're doing a sync with factory) ?
> 
> Thanks

They look good. I just ping-ed them on slack. Let us see how quickly it will go.