Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21733

Опубликовано: 19 янв. 2024
Источник: redhat
CVSS3: 5.3
EPSS Средний

Описание

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

An information disclosure vulnerability was found in Apache Tomcat. Incomplete POST requests triggered an error response that could contain data from a previous HTTP request. This flaw allows a remote attacker to access files from another user that should be otherwise prevented by limits or authentication.

Отчет

Red Hat Enterprise Linux remains unaffected as the vulnerable version of Tomcat (e.g., versions 8.5.7 through 8.5.63 and 9.0.0 through 9.0.43) has not been shipped or included.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2tomcatNot affected
Red Hat AMQ Broker 7tomcatNot affected
Red Hat build of Apache Camel for Spring Boot 3tomcatNot affected
Red Hat Build of KeycloaktomcatNot affected
Red Hat build of OptaPlanner 8tomcatNot affected
Red Hat Data Grid 8tomcatNot affected
Red Hat Decision Manager 7tomcatNot affected
Red Hat Enterprise Linux 6tomcat6Not affected
Red Hat Enterprise Linux 7tomcatNot affected
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-209
https://bugzilla.redhat.com/show_bug.cgi?id=2259204tomcat: Leaking of unrelated request bodies in default error page

EPSS

Процентиль: 98%
0.65426
Средний

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

CVSS3: 5.3
nvd
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

CVSS3: 5.3
debian
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerabi ...

suse-cvrf
больше 1 года назад

Security update for tomcat

CVSS3: 5.3
github
больше 1 года назад

Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information

EPSS

Процентиль: 98%
0.65426
Средний

5.3 Medium

CVSS3