Junglewise Threat Intelligence

CVE-2023-42795: Apache Tomcat information leak via incomplete object cleanup

CVE-2023-42795 · Severity: medium · CVSS 5.3 · Published 2023-10-10

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely used web server and application container, is affected by a flaw that fails to properly clear data between user requests. This could allow sensitive information from one user's session to leak into another user's session. Organizations should update to a patched version to prevent potential data exposure.

Technical details

Apache Tomcat contains an incomplete cleanup vulnerability (CWE-459) during the recycling of internal objects. When an error occurs during the recycling process, Tomcat may skip certain cleanup steps, causing data from a previous request or response to persist and be accessible to a subsequent, unrelated request. This is a network-based attack that requires no authentication or user interaction. The vulnerability affects multiple major versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.x. Patches have been released in versions 8.5.94, 9.0.81, 10.1.14, and 11.0.0-M12.

Affected products

  • Apache Tomcat 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.80, 10.1.0-M1 to 10.1.13, 11.0.0-M1 to 11.0.0-M11

Timeline

  • 2023-10-10: disclosed
  • 2023-10-10: advisory

References

Related threats