QID 980269

QID 980269: Java (maven) Security Update for org.apache.tomcat:tomcat (GHSA-4vww-mc66-62m6)

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-4vww-mc66-62m6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980269

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4vww-mc66-62m6 org.apache.tomcat:tomcat URL Logo github.com/advisories/GHSA-4vww-mc66-62m6