Search CVE reports


Toggle filters

21 – 30 of 72 results


CVE-2024-52317

Medium priority

Some fixes available 1 of 4

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat10, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Not affected
tomcat10 Fixed Not in release Not in release
tomcat9 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-52316

Medium priority

Some fixes available 1 of 8

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat10, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat10 Fixed Not in release Not in release
tomcat9 Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-38286

Medium priority

Some fixes available 8 of 9

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat10, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat10 Fixed Not in release Not in release
tomcat9 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-22029

Medium priority
Ignored

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat10, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Not affected
tomcat10 Not affected Not in release Not in release
tomcat9 Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-34750

Medium priority

Some fixes available 6 of 10

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a...

5 affected packages

tomcat10, tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Fixed Not in release Not in release
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Not affected
tomcat9 Fixed Fixed Ignored Ignored
Show less packages

CVE-2024-24549

Medium priority

Some fixes available 9 of 11

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat10, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
tomcat8 Not in release Not in release Not in release Fixed
tomcat10 Fixed Not in release Not in release
tomcat9 Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-23672

Medium priority

Some fixes available 9 of 15

Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Needs evaluation
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
tomcat10 Fixed Not in release Not in release
Show less packages

CVE-2024-21733

Medium priority

Some fixes available 3 of 13

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also...

5 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Needs evaluation
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Not affected Not affected Fixed Fixed
tomcat10 Not affected Not in release Not in release Not in release
Show less packages

CVE-2023-46589

Medium priority

Some fixes available 8 of 12

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer...

3 affected packages

tomcat10, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-45648

Medium priority

Some fixes available 8 of 13

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer...

3 affected packages

tomcat10, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Ignored
tomcat8 Not in release Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
Show less packages