CVE-2024-52317 - tomcat-embed-core in folio-keycloak - Analysis of vulnerability - Ramsons bugfix

Description

Severity: medium
Link:
Package Name: tomcat-embed-core

Current version: 10.1.30 / fixed in 11.0.0, 10.1.31, 9.0.96

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat.

Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

Modules impacted:

folio-keycloak

Eureka

25.0.5.tl

Checklist

hide

Activity

Show:

Julian Ladisch January 13, 2025 at 5:10 PM

Denis confirms that this Jira is a copy&paste error and should be ignored.

Julian Ladisch December 19, 2024 at 4:32 PM

Can we get more information where in the image the tomcat-embed-core is?

Julian Ladisch December 10, 2024 at 12:10 PM
Edited

: I cannot find the version 25.0.5.tl:

I cannot find tomcat-embed-core in the docker image when manually building using

Won't Do

Details

Assignee

Reporter

Priority

RCA Group

TBD

Labels

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs
Created December 10, 2024 at 12:03 PM
Updated January 13, 2025 at 5:11 PM
Resolved January 13, 2025 at 5:10 PM
TestRail: Cases
TestRail: Runs