Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-42795
HistoryOct 10, 2023 - 12:00 a.m.

CVE-2023-42795

2023-10-1000:00:00
ubuntu.com
ubuntu.com
56
apache tomcat
incomplete cleanup
information leaking
upgrade
version 8.5.0
version 11.0.0-m11

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.01 Low

EPSS

Percentile

83.5%

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various
internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from
10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0
through 8.5.93, an error could cause Tomcat to skip some parts of the
recycling process leading to information leaking from the current
request/response to the next. Users are recommended to upgrade to version
11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards,
which fixes the issue.

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

0.01 Low

EPSS

Percentile

83.5%