VDB
Sign up
HIGH7.5

GHSA-69r9-qgr7-g2wj

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

Quick fix

GHSA-69r9-qgr7-g2wj — org.apache.tomcat:tomcat-tribes: upgrade to the fixed version with the command below.

# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-tribes

Details

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.tomcat:tomcat-tribes
Introduced in: 11.0.20Fixed in: 11.0.21
Fix# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-tribes
Maven/org.apache.tomcat:tomcat-tribes
Introduced in: 10.1.53Fixed in: 10.1.54
Fix# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-tribes
Maven/org.apache.tomcat:tomcat-tribes
Introduced in: 9.0.116Fixed in: 9.0.117
Fix# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribes
Maven/org.apache.tomcat:tomcat
Introduced in: 11.0.20Fixed in: 11.0.21
Fix# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat
Introduced in: 10.1.53Fixed in: 10.1.54
Fix# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat
Maven/org.apache.tomcat:tomcat
Introduced in: 9.0.116Fixed in: 9.0.117
Fix# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat

References