Executive brief
Apache Tomcat, a widely used web server and application container, is affected by a flaw that fails to properly clear data between user requests. This could allow sensitive information from one user's session to leak into another user's session. Organizations should update to a patched version to prevent potential data exposure.
Technical details
Apache Tomcat contains an incomplete cleanup vulnerability (CWE-459) during the recycling of internal objects. When an error occurs during the recycling process, Tomcat may skip certain cleanup steps, causing data from a previous request or response to persist and be accessible to a subsequent, unrelated request. This is a network-based attack that requires no authentication or user interaction. The vulnerability affects multiple major versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.x. Patches have been released in versions 8.5.94, 9.0.81, 10.1.14, and 11.0.0-M12.
Affected products
- Apache Tomcat 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.80, 10.1.0-M1 to 10.1.13, 11.0.0-M1 to 11.0.0-M11
Timeline
- 2023-10-10: disclosed
- 2023-10-10: advisory