This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f632-9449-3j4w | Apache Tomcat - XSS in generated JSPs |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 15 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache tomcat |
|
| CPEs | cpe:2.3:a:apache:tomcat:10.1.31:*:*:*:*:*:*:* cpe:2.3:a:apache:tomcat:11.0.0:-:*:*:*:*:*:* cpe:2.3:a:apache:tomcat:9.0.96:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache tomcat |
Fri, 31 Jan 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 18 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-326 | |
| Metrics |
cvssV3_1
|
Mon, 18 Nov 2024 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue. | |
| Title | Apache Tomcat: Incorrect JSP tag recycling leads to XSS | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-01-31T15:02:49.374Z
Reserved: 2024-11-07T07:48:18.086Z
Link: CVE-2024-52318
Updated: 2025-01-31T15:02:49.374Z
Status : Analyzed
Published: 2024-11-18T13:15:04.490
Modified: 2025-05-15T17:46:50.373
Link: CVE-2024-52318
OpenCVE Enrichment
No data.
Github GHSA