CVE-2024-52317 Affecting tomcat10 package, versions <10.1.31-1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIANUNSTABLE-TOMCAT10-8383893
- published 19 Nov 2024
- disclosed 18 Nov 2024
How to fix?
Upgrade Debian:unstable
tomcat10
to version 10.1.31-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream tomcat10
package and not the tomcat10
package as distributed by Debian
.
See How to fix?
for Debian:unstable
relevant fixed versions and status.
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.