Overview
About vulnerability
Applications that parse ETags from “If-Match” or “If-None-Match” request headers are vulnerable to DoS attack.
Users of affected versions should upgrade to the corresponding fixed version.
Users of older, unsupported versions could enforce a size limit on “If-Match” and “If-None-Match” headers, e.g. through a Filter.
Details
- Affected product:
- Apache CXF , Apache Log4j , Apache Struts , Apache Tapestry , Apache Tomcat , Eclipse Jetty , Spring , activemq , camel , cocoon , crash , glassfish-hk2 , jersey , karaf , taglibs-standard-impl , tika
- Affected packages:
- Spring Batch @ 4.3.10 (+4274 more)
Applications that parse ETags from “If-Match” or “If-None-Match” request headers are vulnerable to DoS attack.
Users of affected versions should upgrade to the corresponding fixed version.
Users of older, unsupported versions could enforce a size limit on “If-Match” and “If-None-Match” headers, e.g. through a Filter.