Apache Tomcat vulnerable to information leak
High severity
GitHub Reviewed
Published
Jun 21, 2023
to the GitHub Advisory Database
•
Updated Oct 9, 2024
Description
Published by the National Vulnerability Database
Jun 21, 2023
Published to the GitHub Advisory Database
Jun 21, 2023
Reviewed
Jun 21, 2023
Last updated
Oct 9, 2024
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS message would be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
References