Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-42795

Опубликовано: 10 окт. 2023
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

A flaw was found in Apache Tomcat. Tomcat may skip, after an error, the recycling of the internal objects that the next request/response process might use, resulting in information leaking from one request to the next. This flaw allows a malicious user to have access to this information.

Отчет

Red Hat rates this as a Moderate impact as the confidentiality is not fully compromised and the malicious user does not have confirmation over the scenario to replicate the error and capture the possible jeopardizing response.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2tomcatNot affected
Red Hat AMQ Broker 7tomcatNot affected
Red Hat build of Apache Camel for Spring Boot 3tomcatWill not fix
Red Hat build of OptaPlanner 8tomcatWill not fix
Red Hat Data Grid 8tomcatNot affected
Red Hat Decision Manager 7tomcatFix deferred
Red Hat Enterprise Linux 7tomcatWill not fix
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 8pki-servlet-containerNot affected
Red Hat Enterprise Linux 9pki-servlet-engineWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-459
https://bugzilla.redhat.com/show_bug.cgi?id=2243752tomcat: improper cleaning of recycled objects could lead to information leak

EPSS

Процентиль: 66%
0.00525
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.3
nvd
больше 1 года назад

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS3: 5.3
debian
больше 1 года назад

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling vario ...

CVSS3: 5.3
github
больше 1 года назад

Apache Tomcat Incomplete Cleanup vulnerability

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость сервера приложений Apache Tomcat существует из-за неполной очистки временных или вспомогательных ресурсов, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 66%
0.00525
Низкий

5.3 Medium

CVSS3