QID 150695
Date Published: 2023-06-28
QID 150695: Apache Tomcat Information Disclosure Vulnerability (CVE-2023-34981)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
The fix for bug 66512 introduced a regression in Apache Tomcat, if a response did not have any HTTP headers set, no AJP SEND_HEADERS message would be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
Affected Products:
Apache Tomcat 11.0.0-M5
Apache Tomcat 10.1.8
Apache Tomcat 9.0.74
Apache Tomcat 8.5.88
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation of the vulnerability could disclose sensitive information to an attacker.
- Apache Security -
lists.apache.org/thread/j1ksjh9m9gx1q60rtk1sbzmxhvj5h5qz
CVEs related to QID 150695
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat Downloads |
|