Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 19, 2024
Package
Affected versions
>= 6.0.30, <= 6.0.33
>= 7.0, < 7.0.22
Patched versions
6.0.35
7.0.22
Description
Published by the National Vulnerability Database
Jan 19, 2012
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Jan 19, 2024
Last updated
Jan 19, 2024
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
References