QID 996809
Date Published: 2024-01-23
QID 996809: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-rp8h-vr48-4j8p)
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-rp8h-vr48-4j8p for updates and patch information.
Vendor References
- GHSA-rp8h-vr48-4j8p -
github.com/advisories/GHSA-rp8h-vr48-4j8p
CVEs related to QID 996809
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rp8h-vr48-4j8p | org.apache.tomcat:tomcat |
|