Lucene search

K
githubGitHub Advisory DatabaseGHSA-MPPV-79CH-VW6Q
HistoryJun 21, 2023 - 12:30 p.m.

Apache Tomcat vulnerable to information leak

2023-06-2112:30:19
GitHub Advisory Database
github.com
30
apache
tomcat
info leak
bug
regression
http headers
ajp proxy.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.6%

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS message would be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

Affected configurations

Vulners
Node
org.apache.tomcat\tomcatMatchcoyote8.5.88
OR
embed_pdf_projectembed_pdfMatch9.0.74
OR
embed_pdf_projectembed_pdfMatch10.1.8
OR
embed_pdf_projectembed_pdfMatch11.0.0-m5

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.3 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.6%