Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-34981
HistoryJun 21, 2023 - 12:00 a.m.

CVE-2023-34981

2023-06-2100:00:00
ubuntu.com
ubuntu.com
18
apache
tomcat
ajp proxy

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

69.0%

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8,
9.0.74 and 8.5.88 meant that, if a response did not include any HTTP
headers no AJP SEND_HEADERS messare woudl be sent for the response which in
turn meant that at least one AJP proxy (mod_proxy_ajp) would use the
response headers from the previous request leading to an information leak.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.003

Percentile

69.0%