Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-qvf5-hvjx-wm27: Apache Tomcat Request and/or response mix-up

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.

This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.

Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

ghsa
#vulnerability#web#apache#git#java#maven

Skip to content

Navigation Menu

    • GitHub Copilot

      Write better code with AI

    • Security

      Find and fix vulnerabilities

    • Actions

      Automate any workflow

    • Codespaces

      Instant dev environments

    • Issues

      Plan and track work

    • Code Review

      Manage code changes

    • Discussions

      Collaborate outside of code

    • Code Search

      Find more, search less

  • Explore

    • Learning Pathways
    • White papers, Ebooks, Webinars
    • Customer Stories
    • Partners
    • GitHub Sponsors

      Fund open source developers

*   The ReadME Project
    
    GitHub community articles
    • Enterprise platform

      AI-powered developer platform

  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2024-52317

Apache Tomcat Request and/or response mix-up

Moderate severity GitHub Reviewed Published Nov 18, 2024 to the GitHub Advisory Database • Updated Nov 18, 2024

Package

maven org.apache.tomcat.embed:tomcat-embed-core (Maven)

Affected versions

>= 9.0.92, < 9.0.96

>= 10.1.27, < 10.1.31

>= 11.0.0-M23, < 11.0.0

Patched versions

9.0.96

10.1.31

11.0.0

maven org.apache.tomcat:tomcat-coyote (Maven)

>= 9.0.92, < 9.0.96

>= 10.1.27, < 10.1.31

>= 11.0.0-M23, < 11.0.0

Description

Published to the GitHub Advisory Database

Nov 18, 2024

Last updated

Nov 18, 2024

ghsa: Latest News

GHSA-jh6x-7xfg-9cq2: Searching Opencast may cause a denial of service