Description
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Remediation
References
Related Vulnerabilities
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2010-2950)
WordPress Plugin Tracking Code Manager Multiple Vulnerabilities (1.11.1)
WordPress Plugin Restaurant Menu by MotoPress Cross-Site Scripting (2.4.1)
WordPress Plugin Google Captcha (reCAPTCHA) by BestWebSoft Cross-Site Scripting (1.05)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7951)