A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 09 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-13T16:55:41.813Z

Reserved: 2023-06-08T12:48:27.995Z

Link: CVE-2023-34981

cve-icon Vulnrichment

Updated: 2024-08-02T16:17:04.269Z

cve-icon NVD

Status : Modified

Published: 2023-06-21T11:15:09.410

Modified: 2024-11-21T08:07:46.027

Link: CVE-2023-34981

cve-icon Redhat

Severity : Important

Publid Date: 2023-06-21T00:00:00Z

Links: CVE-2023-34981 - Bugzilla

cve-icon OpenCVE Enrichment

No data.