VDB
EN
HIGH 7.5

GHSA-j39c-c8hj-x4j3

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

빠른 조치

GHSA-j39c-c8hj-x4j3 — org.apache.tomcat.embed:tomcat-embed-core: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>10.0.2</version> for org.apache.tomcat.embed:tomcat-embed-core

상세

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 10.0.0-M1 수정 버전: 10.0.2
수정 # pom.xml: bump <version>10.0.2</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 9.0.0-M1 수정 버전: 9.0.43
수정 # pom.xml: bump <version>9.0.43</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 8.5.0 수정 버전: 8.5.63
수정 # pom.xml: bump <version>8.5.63</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat:tomcat-coyote
최초 영향 버전: 10.0.0-M1 수정 버전: 10.0.2
수정 # pom.xml: bump <version>10.0.2</version> for org.apache.tomcat:tomcat-coyote

참고