CVE-2024-52317 - tomcat-embed-core mix-up - Analysis of vulnerability - Ramsons bugfix

Description

Severity: medium
Link:
Package Name: tomcat-embed-core

Current version: 10.1.30 / fixed in 11.0.0, 10.1.31, 9.0.96

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat.

Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

Modules impacted:

mod-roles-keycloak

Eureka

2.0.4 … 2.0.8

mod-okapi-facade

Eureka

2.0.0 … 2.0.1

mod-data-export

Firebird

5.1.1

mod-data-export-spring

Firebird

3.4.1

mod-remote-storage

Volaris 

3.3.1

mod-ebsconet

Thunderjet

2.3.0

folio-keycloak

Eureka

25.0.5.tl

cloned into

Checklist

hide

Activity

Show:
Unresolved

Details

Assignee

Reporter

Priority

RCA Group

TBD

Labels

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs
Created December 9, 2024 at 4:02 PM
Updated January 16, 2025 at 4:35 PM
TestRail: Cases
TestRail: Runs