Omar Aljabr’s Post

View profile for Omar Aljabr, graphic

OSCP | eCPPTv2 | cybersecurity researcher، penetration tester, Bug hunter

🚨Alert🚨CVE-2024-34750: Apache Tomcat DoS vulnerability in HTTP/2 connector 📊50.3K+ Services are found on hunter.how 🔗Hunter Link: https://lnkd.in/dT6es5PG 👇Search Query Hunter: web.title="Apache Tomcat/9.0.0"||web.title="Apache Tomcat/10.1.0"||web.title="Apache Tomcat/11.0.0" ⚖When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. 📰Report: https://lnkd.in/di2GWDYy 📰Refer: https://lnkd.in/d9Yb6RFk #Tomcat #Apache #hunterhow #infosec #infosecurity #Infosys #Vulnerability

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics