GHSA-j39c-c8hj-x4j3HighCVSS 7.5

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

Published
June 16, 2021
Last Modified
June 5, 2026

🔗 CVE IDs covered (1)

📋 Description

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

🎯 Affected products4

  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 8.5.0, < 8.5.63
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.0.0-M1, < 10.0.2
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 9.0.0-M1, < 9.0.43
  • maven/org.apache.tomcat:tomcat-coyote:>= 10.0.0-M1, < 10.0.2

🔗 References (18)