QID 996928
Date Published: 2024-01-29
QID 996928: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-c38m-v4m2-524v)
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c38m-v4m2-524v for updates and patch information.
Vendor References
- GHSA-c38m-v4m2-524v -
github.com/advisories/GHSA-c38m-v4m2-524v
CVEs related to QID 996928
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c38m-v4m2-524v | org.apache.tomcat:tomcat |
|