CVE-2019-0199: Uncontrolled Resource Consumption
(updated )
The HTTP/2 implementation in Apache Tomcat accepted streams with excessive numbers of SETTINGS
frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API’s blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
References
Detect and mitigate CVE-2019-0199 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →