CVE-2023-42795

Aliases:GHSA-g8pj-r55q-5c2vBIT-tomcat-2023-42795
Advisory lineage Upstream: 0 Downstream: 16
Modified
Published: 10 Oct 2023, 17:42
Last modified:29 Oct 2025, 12:02

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.71% LOW
1% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Oct 2023, 17:42
Published
Vulnerability first disclosed
29 Oct 2025, 12:02
Last Modified
Vulnerability information updated

Description

Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS Trends

Current EPSS score: 0.71% Percentile: 73%

Techniques & Countermeasures

  • CWE-459Incomplete Cleanup

    The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.0-M11 | ≥ 10.1.0-M1, ≤ 10.1.13 | ≥ 9.0.0-M1, ≤ 9.0.80 | ≥ 8.5.0, ≤ 8.5.93

  • UnknownTomcat

    ≥ 8.5.0, < 8.5.94 | ≥ 9.0.1, < 9.0.81 | ≥ 10.1.1, < 10.1.14 | 9.0.0:milestone1 | 9.0.0:milestone10 | 9.0.0:milestone11 | 9.0.0:milestone12 | 9.0.0:milestone13 | 9.0.0:milestone14 | 9.0.0:milestone15 | 9.0.0:milestone16 | 9.0.0:milestone17 | 9.0.0:milestone18 | 9.0.0:milestone19 | 9.0.0:milestone2 | 9.0.0:milestone20 | 9.0.0:milestone21 | 9.0.0:milestone22 | 9.0.0:milestone23 | 9.0.0:milestone24 | 9.0.0:milestone25 | 9.0.0:milestone26 | 9.0.0:milestone27 | 9.0.0:milestone3 | 9.0.0:milestone4 | 9.0.0:milestone5 | 9.0.0:milestone6 | 9.0.0:milestone7 | 9.0.0:milestone8 | 9.0.0:milestone9 | 10.1.0:milestone1 | 10.1.0:milestone10 | 10.1.0:milestone11 | 10.1.0:milestone12 | 10.1.0:milestone13 | 10.1.0:milestone14 | 10.1.0:milestone15 | 10.1.0:milestone16 | 10.1.0:milestone17 | 10.1.0:milestone18 | 10.1.0:milestone19 | 10.1.0:milestone2 | 10.1.0:milestone20 | 10.1.0:milestone3 | 10.1.0:milestone4 | 10.1.0:milestone5 | 10.1.0:milestone6 | 10.1.0:milestone7 | 10.1.0:milestone8 | 10.1.0:milestone9 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone2 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9

  • debiandebian_linux

    10.0 | 11.0 | 12.0

  • org.apache.tomcattomcat

    ≥ 9.0.0-M1, < 9.0.81 | ≥ 8.5.0, < 8.5.94

  • org.apache.tomcattomcat-coyote

    ≥ 11.0.0-M1, < 11.0.0-M12 | ≥ 10.1.0-M1, < 10.1.14

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 11.0.0-M1, < 11.0.0-M12 | ≥ 10.1.0-M1, < 10.1.14 | ≥ 9.0.0-M1, < 9.0.81 | ≥ 8.5.0, < 8.5.94

References (13)