/
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-cpp4-5m88-q764

Published

Last updated

https://images.chainguard.dev/security/CGA-cpp4-5m88-q764
Package

tomcat

RepositoryWolfi
Latest Update
Under investigation
Aliases
  • CVE-2023-42795
  • GHSA-g8pj-r55q-5c2v

Severity

Unknown

Summary

Apache Tomcat Incomplete Cleanup vulnerability

Description

Incomplete Cleanup vulnerability in Apache Tomcat.

When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next.

Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs