CVE-2024-21733: Apache Tomcat: Leaking of unrelated request bodies in default error page
Apache Tomcat could allow a remote attacker to obtain sensitive information, caused by the leaking of unrelated request bodies in default error page. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
Other sources
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.
Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
— GitHub
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.
Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
— NVD
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected.
Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.64 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 9.0.44 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.44 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.64 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.64 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.44
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21733?
CVE-2024-21733 has been classified as a moderate severity vulnerability that could lead to information disclosure.
What versions of Apache Tomcat are affected by CVE-2024-21733?
CVE-2024-21733 affects Apache Tomcat versions 8.5.7 to 8.5.64 and 9.0.1 to 9.0.44, including several milestone versions.
How do I fix CVE-2024-21733?
To fix CVE-2024-21733, upgrade Apache Tomcat to version 8.5.64 or 9.0.44.
What type of information can be leaked due to CVE-2024-21733?
CVE-2024-21733 can potentially leak unrelated request bodies through the default error page.
Is CVE-2024-21733 a remote vulnerability?
Yes, CVE-2024-21733 allows a remote attacker to exploit the vulnerability by sending a specially crafted request.