Описание
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | not-affected  | 10.1.40-1 | 
| esm-apps/noble | released  | 10.1.16-1ubuntu0.1~esm3 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | needed  | |
| oracular | ignored  | end of life, was needed | 
| plucky | not-affected  | 10.1.35-1 | 
| questing | not-affected  | 10.1.40-1 | 
| upstream | released  | 10.1.31 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/xenial | not-affected  | code not present | 
| esm-infra-legacy/trusty | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/bionic | not-affected  | code not present | 
| esm-apps/xenial | not-affected  | code not present | 
| esm-infra-legacy/trusty | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-apps/bionic | not-affected  | code not present | 
| esm-infra/focal | DNE  | |
| esm-infra/xenial | not-affected  | code not present | 
| focal | DNE  | |
| jammy | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | needed  | |
| esm-apps/bionic | not-affected  | code not present | 
| esm-apps/focal | not-affected  | code not present | 
| esm-apps/jammy | not-affected  | code not present | 
| esm-apps/noble | not-affected  | code not present | 
| focal | ignored  | end of standard support, was needs-triage | 
| jammy | not-affected  | code not present | 
| noble | not-affected  | code not present | 
| oracular | ignored  | end of life, was needs-triage | 
| plucky | not-affected  | code not present | 
Показывать по
Ссылки на источники
6.5 Medium
CVSS3
Связанные уязвимости
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. ...
Уязвимость сервера приложений Apache Tomcat, связанная с недостаточно стойким шифрованием данных, позволяющая нарушителю выполнить произвольный код
6.5 Medium
CVSS3