Back

HIGH

tomcat: Information leak between requests on the same connection

Published Mar 14, 2017

Description

An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (26)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 14, 2017
Updated Oct 15, 2024
Reserved Oct 18, 2016
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 13, 2017
GHSA-FJWP-R6FM-Q6QW