Description
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1844 | A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak. |
Github GHSA |
GHSA-mppv-79ch-vw6q | Apache Tomcat vulnerable to information leak |
References
History
Wed, 09 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-732 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-02-13T16:55:41.813Z
Reserved: 2023-06-08T12:48:27.995Z
Link: CVE-2023-34981
Updated: 2024-08-02T16:17:04.269Z
Status : Modified
Published: 2023-06-21T11:15:09.410
Modified: 2024-11-21T08:07:46.027
Link: CVE-2023-34981
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA