GHSA-f4qf-m5gf-8jm8MediumCVSS 5.3

Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information

Published
January 19, 2024
Last Modified
June 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.

Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

🎯 Affected products5

  • maven/org.apache.tomcat:tomcat-coyote:>= 9.0.0-M11, < 9.0.44
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 8.5.7, < 8.5.64
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 9.0.0-M11, < 9.0.44
  • maven/org.apache.tomcat:tomcat-coyote:>= 8.5.7, < 8.5.64
  • maven/org.apache.tomcat.experimental:tomcat-embed-programmatic:>= 9.0.43, < 9.0.44

🔗 References (11)