CVE-2023-42795
published 2023-10-10CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.16%
80.2th percentile
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the current request/response to the next.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.1 < 10.1.14 | 10.1.14 |
| apache | tomcat | >= 8.5.0 < 8.5.94 | 8.5.94 |
| apache | tomcat | >= 9.0.1 < 9.0.81 | 9.0.81 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.13 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M11 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.93 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.80 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv5.3MEDIUM
vendor_apache5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-11-13·CVSS 4.3
CVE-2023-45648 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tom
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Red Hat
tomcat: improper cleaning of recycled objects could lead to information leak
vendor_redhat·2023-10-10·CVSS 5.3
CVE-2023-42795 [MEDIUM] CWE-459 tomcat: improper cleaning of recycled objects could lead to information leak
tomcat: improper cleaning of recycled objects could lead to information leak
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the current request/response to the next.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
A flaw was found in Apache Tomcat. Tomcat may skip, after an error, the recycling of the internal objects that the next request/response process might use, r
Debian
CVE-2023-42795: tomcat10 - Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various interna...
vendor_debian·2023·CVSS 5.3
CVE-2023-42795 [MEDIUM] CVE-2023-42795: tomcat10 - Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various interna...
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u1)
forky: resolved (fixed in 10.1.14-1)
sid: resolved (fixed in 10.1.14-1)
trixie: resolved (fixed in 10.1.14-1)
Apache
Apache tomcat: CVE-2023-42795
vendor_apache·CVSS 5.3
CVE-2023-42795 [MEDIUM] Apache tomcat: CVE-2023-42795
Apache tomcat: CVE-2023-42795
When recycling various internal objects, including the request and the response, prior to re-use by the next request/response, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. This was fixed with commit 30f8063d . This issue was identified by the Tomcat Security Team on 13 September 2023. The issue was made public on 10 October 2023. Affects: 8.5.0 to 8.5.93 Low: Denial of Service
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
OSV
tomcat9 vulnerabilities
osv·2024-11-13·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A
remote attacke
OSV
CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat
osv·2023-10-10·CVSS 5.3
CVE-2023-42795 [MEDIUM] CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
GHSA
Apache Tomcat Incomplete Cleanup vulnerability
ghsa·2023-10-10
CVE-2023-42795 [MEDIUM] CWE-459 Apache Tomcat Incomplete Cleanup vulnerability
Apache Tomcat Incomplete Cleanup vulnerability
Incomplete Cleanup vulnerability in Apache Tomcat.
When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
OSV
Apache Tomcat Incomplete Cleanup vulnerability
osv·2023-10-10
CVE-2023-42795 [MEDIUM] Apache Tomcat Incomplete Cleanup vulnerability
Apache Tomcat Incomplete Cleanup vulnerability
Incomplete Cleanup vulnerability in Apache Tomcat.
When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-42795 tomcat: improper cleaning of recycled objects could lead to information leak
bugzilla·2023-10-12·CVSS 5.3
CVE-2023-42795 [MEDIUM] CVE-2023-42795 tomcat: improper cleaning of recycled objects could lead to information leak
CVE-2023-42795 tomcat: improper cleaning of recycled objects could lead to information leak
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the current request/response to the next.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
https://lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lw
http://www.openwall.com/lists/oss-security/2023/10/10/9
https://www.debian.org/security/2023/dsa-5522
https://www.deb
Qualys
CVE-2023-44487 HTTP/2 Rapid Reset Attack
blogs_qualys·2023-10-10·CVSS 7.5
CVE-2023-44487 [HIGH] CVE-2023-44487 HTTP/2 Rapid Reset Attack
## Table of Contents
What is CVE-2023-44487 HTTP/2 Rapid Reset Attack?
What should organizations do?
How can Qualys Help?
Conclusion
Additional Contributors:
Today, Amazon Web Services , Cloudflare , and Google , in a coordinated announcement, reveal their experiences mitigating powerful HTTP/2-based DDoS attacks utilizing a zero-day technique referred to as ‘Rapid Reset’, documented under the vulnerability identifier CVE-2023-44487. The attack magnitudes reported are astonishing: Amazon mitigated attacks at a rate of 155 million requests per second, Cloudflare at 201 million rps, and Google endured a record-breaking 398 million rps. This vulnerability was under active attack in August.
## What is CVE-2023-44487 HTTP/2 Rapid Reset Attack?
The ‘Rapid Reset’ technique leverages the ‘
https://lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lwhttp://www.openwall.com/lists/oss-security/2023/10/10/9https://lists.apache.org/thread/065jfyo583490r9j2v73nhpyxdob56lwhttps://lists.debian.org/debian-lts-announce/2023/10/msg00020.htmlhttps://security.netapp.com/advisory/ntap-20231103-0007/https://www.debian.org/security/2023/dsa-5521https://www.debian.org/security/2023/dsa-5522
2023-10-10
Published