Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests
could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
References
Configurations
No configuration.
History
24 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-11-18 12:15
Updated : 2025-01-24 20:15
NVD link : CVE-2024-52317
Mitre link : CVE-2024-52317
CVE.ORG link : CVE-2024-52317
JSON object : View
Products Affected
No product.
CWE
CWE-326
Inadequate Encryption Strength