CVE-2024-21733
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
- Affected products
- Alt Linux, Apache Tomcat, Astra Linux, Linuxmint, Suse, Ubuntu
- Apache Tomcat
- < 8.5.64, 9.0.44, 9.0.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 14.3% (96th percentile)
- Weakness
- CWE-209
- NVD status
- Modified
- Published
- 2024-01-19
CVE-2024-21733 at NVD
3 known exploits for CVE-2024-21733
Proof-of-concept code and exploit modules indexed by Sploitus