Back

LOW

tomcat: Information disclosure in asynchronous context when using AsyncListeners that threw RuntimeExceptions

Published Jun 1, 2013

Description

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

Affected products

Remediation

Red Hat statement

This flaw only affects tomcat 7. Tomcat 5 and 6 are not affected. The jbossweb servlet container is also not affected.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jun 1, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date May 10, 2013
GHSA-3P5R-7CW3-2M67