CVE-2024-21733
Vulnerability Summary
Timeline
Description
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 70.95%• Percentile: 99%
Techniques & Countermeasures
- CWE-209•Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Affected Systems
- apache software foundation•apache tomcat
≥ 8.5.7, ≤ 8.5.63 | ≥ 9.0.0-M11, ≤ 9.0.43
- Unknown•Tomcat
≥ 8.5.7, < 8.5.64 | ≥ 9.0.1, < 9.0.44 | 9.0.0:milestone11 | 9.0.0:milestone12 | 9.0.0:milestone13 | 9.0.0:milestone14 | 9.0.0:milestone15 | 9.0.0:milestone16 | 9.0.0:milestone17 | 9.0.0:milestone18 | 9.0.0:milestone19 | 9.0.0:milestone20 | 9.0.0:milestone21 | 9.0.0:milestone22 | 9.0.0:milestone23 | 9.0.0:milestone24 | 9.0.0:milestone25 | 9.0.0:milestone26 | 9.0.0:milestone27
- org.apache.tomcat•tomcat-coyote
≥ 9.0.0-M11, < 9.0.44
- org.apache.tomcat.embed•tomcat-embed-core
≥ 8.5.7, < 8.5.64
References (12)
- https://lists.apache.org/thread/h9bjqdd0odj6lhs2o96qgowcc6hb0cfz
- http://www.openwall.com/lists/oss-security/2024/01/19/2
- http://packetstormsecurity.com/files/176951/Apache-Tomcat-8.5.63-9.0.43-HTTP-Response-Smuggling.html
- https://security.netapp.com/advisory/ntap-20240216-0005/
- https://lists.debian.org/debian-lts-announce/2025/01/msg00009.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-21733
- https://github.com/apache/tomcat/commit/86ccc43940861703c2be96a5f35384407522125a
- https://github.com/apache/tomcat/commit/ce4b154e7b48f66bd98858626347747cd2514311
- https://github.com/apache/tomcat
- https://security.netapp.com/advisory/ntap-20240216-0005
- https://tomcat.apache.org/security-8.html
- https://tomcat.apache.org/security-9.html