CVE-2023-42795
Summary
| CVE | CVE-2023-42795 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-10 18:15:00 UTC |
| Updated | 2023-11-04 06:15:00 UTC |
| Description | Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the current request/response to the next.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5522-1 tomcat9 |
MISC |
www.debian.org |
|
| [SECURITY] [DLA 3617-1] tomcat9 security update |
MISC |
lists.debian.org |
|
| oss-security - CVE-2023-42795: Apache Tomcat: Failure during request clean-up leads
to sensitive data leaking to subsequent requests |
MISC |
www.openwall.com |
|
| October 2023 Apache Tomcat Vulnerabilities in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| Debian -- Security Information -- DSA-5521-1 tomcat10 |
MISC |
www.debian.org |
|
| lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lw |
MISC |
lists.apache.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150732 Apache Tomcat Multiple Vulnerabilities (CVE-2023-42795, CVE-2023-44487, CVE-2023-45648)
- 161276 Oracle Enterprise Linux Security Update for tomcat (ELSA-2024-0125)
- 161315 Oracle Enterprise Linux Security Update for tomcat (ELSA-2024-0474)
- 20399 Oracle Database 19c Critical OJVM Patch Update - January 2024
- 20400 Oracle Database 19c Critical Patch Update - January 2024
- 20401 Oracle Database 21c Critical Patch Update - January 2024
- 242835 Red Hat Update for tomcat (RHSA-2024:0474)
- 242881 Red Hat Update for tomcat (RHSA-2024:0125)
- 296106 Oracle Solaris 11.4 Support Repository Update (SRU) 64.157.2 Missing (CPUOCT2023)
- 356456 Amazon Linux Security Advisory for tomcat8 : ALAS-2023-1868
- 356556 Amazon Linux Security Advisory for tomcat : ALAS2TOMCAT8.5-2023-016
- 356581 Amazon Linux Security Advisory for tomcat : ALAS2TOMCAT9-2023-010
- 356628 Amazon Linux Security Advisory for tomcat9 : ALAS2023-2023-415
- 6000246 Debian Security Update for tomcat9 (DSA 5522-1)
- 6000247 Debian Security Update for tomcat10 (DSA 5521-1)
- 6000257 Debian Security Update for tomcat9 (DLA 3617-1)
- 673877 EulerOS Security Update for tomcat (EulerOS-SA-2024-1166)
- 674011 EulerOS Security Update for tomcat (EulerOS-SA-2024-1305)
- 730934 Apache Tomcat Denial of Service Vulnerability (CVE-2023-42794)
- 730935 Apache Tomcat Information Disclosure Vulnerability (CVE-2023-42795)
- 730936 Apache Tomcat Denial of Service Vulnerability (CVE-2023-42794)
- 730937 Apache Tomcat Multiple Vulnerabilities
- 755218 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:4337-1)
- 755250 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:4423-1)
- 755749 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2024:0472-1)
- 941533 AlmaLinux Security Update for tomcat (ALSA-2024:0125)
- 941551 AlmaLinux Security Update for tomcat (ALSA-2024:0474)
- 995552 Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-g8pj-r55q-5c2v)