QID 150695

Date Published: 2023-06-28

QID 150695: Apache Tomcat Information Disclosure Vulnerability (CVE-2023-34981)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

The fix for bug 66512 introduced a regression in Apache Tomcat, if a response did not have any HTTP headers set, no AJP SEND_HEADERS message would be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

Affected Products:
Apache Tomcat 11.0.0-M5
Apache Tomcat 10.1.8
Apache Tomcat 9.0.74
Apache Tomcat 8.5.88

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.

Successful exploitation of the vulnerability could disclose sensitive information to an attacker.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Upgrade to the latest version of Apache Tomcat. For more information regarding this vulnerability please refer to Apache Security.

    CVEs related to QID 150695

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat Downloads URL Logo tomcat.apache.org/whichversion.html