QID 980337
QID 980337: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-j39c-c8hj-x4j3)
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j39c-c8hj-x4j3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j39c-c8hj-x4j3 -
github.com/advisories/GHSA-j39c-c8hj-x4j3
CVEs related to QID 980337
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j39c-c8hj-x4j3 | org.apache.tomcat.embed:tomcat-embed-core |
|