CVE-2024-52317

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-52317
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-52317.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-52317
Aliases
Related
Published
2024-11-18T12:15:18Z
Modified
2024-11-20T07:59:28.216635Z
Summary
[none]
Details

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.

This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.

Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

References

Affected packages

Debian:13 / tomcat10

Package

Name
tomcat10
Purl
pkg:deb/debian/tomcat10?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.31-1

Affected versions

10.*

10.1.6-1
10.1.7-1
10.1.8-1
10.1.9-1
10.1.10-1
10.1.13-1
10.1.14-1
10.1.15-1
10.1.16-1
10.1.20-1
10.1.23-1
10.1.25-1~bpo12+1
10.1.25-1
10.1.25-2
10.1.30-1~bpo12+1
10.1.30-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}