Apache Tomcat Vulnerability: Generation of Error Message Containing Sensitive Information

CVE-2024-21733
5.3MEDIUM

Key Information

Vendor
Apache
Status
Apache Tomcat
Vendor
CVE Published:
19 January 2024

Badges

😄 Trended👾 Exploit Exists🔴 Public PoC📰 News Worthy

Summary

Apache Tomcat is affected by a vulnerability that allows for the generation of error messages containing sensitive information. This vulnerability affects versions 8.5.7 through 8.5.63 and 9.0.0-M11 through 9.0.43. If exploited, an attacker can de-synchronize a victim's browser from the website, allowing for sensitive data to be smuggled from the server and/or client connections. There are known exploits of this vulnerability in the wild, but no specific ransomware groups have been identified as using this exploit. Users are advised to upgrade to version 8.5.64 or 9.0.44, which contain a fix for the vulnerability.

Affected Version(s)

Apache Tomcat <= 8.5.63

Apache Tomcat <= 9.0.43

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability started trending.

  • 👾

    Exploit exists.

  • First article discovered by securityonline.info

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 Proof of Concept(s)6 News Article(s)

Credit

xer0dayz from company Sn1perSecurity LLC
.