Apache Tomcat: Leaking of unrelated request bodies in default error page
Vulnerability Description
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21733
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- xer0dayz from company Sn1perSecurity LLC
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →