Publish GHSA-f4qf-m5gf-8jm8

This commit is contained in:
advisory-database[bot]
2024-02-01 21:03:47 +00:00
parent daf52a8af9
commit cb552d97a4
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f4qf-m5gf-8jm8",
"modified": "2024-01-29T22:30:43Z",
"modified": "2024-02-01T21:03:23Z",
"published": "2024-01-19T12:30:18Z",
"aliases": [
"CVE-2024-21733"
],
"summary": "Generation of Error Message Containing Sensitive Information",
"details": "Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.\n\n",
"summary": "Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information",
"details": "Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.\n\n",
"severity": [
{
"type": "CVSS_V3",
@@ -59,10 +59,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21733"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/tomcat"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/19/2"