Lucene search

K
redhatcveRedhat.comRH:CVE-2020-13934
HistoryJul 15, 2020 - 6:08 a.m.

CVE-2020-13934

2020-07-1506:08:06
redhat.com
access.redhat.com
10

0.912 High

EPSS

Percentile

98.9%

A flaw was found in Apache Tomcat, where an h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests are made, an OutOfMemoryException could occur, leading to a denial of service. The highest threat from this vulnerability is to system availability.