CVE-2008-4308Sensitive Information Exposure in Apache Tomcat

Severity
2.6LOWNVD
EPSS
7.6%
top 8.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 26
Latest updateMay 2

Description

The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.

CVSS vector

AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9

Affected Packages1 packages

NVDapache/tomcat14 versions+13

Patches

🔴Vulnerability Details

3
OSV
Apache Tomcat information disclosure vulnerability2022-05-02
GHSA
Apache Tomcat information disclosure vulnerability2022-05-02
CVEList
CVE-2008-4308: The doRead method in Apache Tomcat 42009-02-26

📋Vendor Advisories

1
Red Hat
tomcat information disclosure vulnerability2009-02-25

💬Community

1
Bugzilla
CVE-2008-4308 tomcat information disclosure vulnerability2009-03-02
CVE-2008-4308 — Sensitive Information Exposure | cvebase