NA

CVE-2024-21733

Published: 19/01/2024 Updated: 16/02/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 up to and including 8.5.63, from 9.0.0-M11 up to and including 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat 9.0.0

apache tomcat

Vendor Advisories

Generation of Error Message Containing Sensitive Information vulnerability in Apache TomcatThis issue affects Apache Tomcat: from 857 through 8563, from 900-M11 through 9043 Users are recommended to upgrade to version 8564 onwards or 9044 onwards, which contain a fix for the issue (CVE-2024-21733) ...
Generation of Error Message Containing Sensitive Information vulnerability in Apache TomcatThis issue affects Apache Tomcat: from 857 through 8563, from 900-M11 through 9043 Users are recommended to upgrade to version 8564 onwards or 9044 onwards, which contain a fix for the issue (CVE-2024-21733) ...
Description<!---->This CVE is under investigation by Red Hat Product Security ...

Exploits

Apache Tomcat suffers from a client-side de-sync vulnerability via HTTP request smuggling Apache Tomcat versions 857 through 8563 and 900-M11 through 9043 are vulnerable ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2024-21733: Apache Tomcat: Leaking of unrelated request bodies in default error page <!--X-Subject-Header-End--> <!--X-Hea ...