Lucene search

K
osvGoogleOSV:GHSA-RP8H-VR48-4J8P
HistoryMay 17, 2022 - 5:33 a.m.

Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests

2022-05-1705:33:28
Google
osv.dev
7

6.3 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.2%

Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.

6.3 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

65.2%