7.5
CVSSv3

CVE-2023-34981

Published: 21/06/2023 Updated: 21/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 10.1.8

apache tomcat 9.0.74

apache tomcat 8.5.88

apache tomcat 11.0.0

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: A regression in the fix for bug 66512 in Apache Tomcat 1100-M5, 1018, 9074 and 8588 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the r ...