Executive brief
Apache Tomcat is a widely used web server for hosting Java-based applications. A flaw in how it handles certain web page components (JSP tags) could allow an attacker to inject malicious scripts into a user's browser. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A regression introduced in a previous improvement caused pooled JSP tags not to be released after use. This failure in the tag lifecycle management results in subsequent tag outputs not being escaped as expected. An attacker can exploit this behavior to perform a Cross-Site Scripting (XSS) attack by injecting malicious content that the server fails to sanitize. The vulnerability affects Apache Tomcat versions 11.0.0, 10.1.31, and 9.0.96. Users should upgrade to versions 11.0.1, 10.1.33, or 9.0.97 to resolve the issue.
Affected products
- Apache Tomcat 11.0.0, 10.1.31, 9.0.96
Timeline
- 2024-11-18: disclosed
- 2024-11-18: advisory