From cb552d97a435e7aaa77b4b7b995d1062b890c73f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 1 Feb 2024 21:03:47 +0000 Subject: [PATCH] Publish GHSA-f4qf-m5gf-8jm8 --- .../GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json b/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json index 5d5d4888371..9ee5c736553 100644 --- a/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json +++ b/advisories/github-reviewed/2024/01/GHSA-f4qf-m5gf-8jm8/GHSA-f4qf-m5gf-8jm8.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-f4qf-m5gf-8jm8", - "modified": "2024-01-29T22:30:43Z", + "modified": "2024-02-01T21:03:23Z", "published": "2024-01-19T12:30:18Z", "aliases": [ "CVE-2024-21733" ], - "summary": "Generation of Error Message Containing Sensitive Information", - "details": "Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.\n\n", + "summary": "Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information", + "details": "Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.\n\nUsers are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.\n\n", "severity": [ { "type": "CVSS_V3", @@ -59,10 +59,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21733" }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/tomcat" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/01/19/2"