CVE-2023-42795
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
- Affected products
- Alt Linux, Almalinux, Apache Tomcat, Astra Linux, Centos, Linuxmint, Red Hat, Red Os
- Apache Tomcat
- < 8.5.94, 9.0.81, 10.1.14, 9.0.0, 10.1.0, 11.0.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-459
- NVD status
- Modified
- Published
- 2023-10-10
CVE-2023-42795 at NVD
1 known exploit for CVE-2023-42795
Proof-of-concept code and exploit modules indexed by Sploitus