Apache Security Update – 21 January 2024

Apache has released a security update to address a vulnerability in multiple versions of Apache Tomcat.

The addressed vulnerability could allow the remote attacker to obtain sensitive information caused by the leaking of unrelated request bodies in the default error page by sending a specially crafted request to the affected system.

Apache Tomcat Information Disclosure Vulnerability (CVE-2024-21733):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Obtain Information

Affected products:

  • Apache Tomcat 8.5.7 through 8.5.63.
  • Apache Tomcat 9.0.0-M11 through 9.0.43.
Vulnerabilities

CVE-2024-21733

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache Tomcat Security Update

References