CVE-2024-52317

CWE-3268 documents7 sources
Severity
6.5MEDIUM
EPSS
21.1%
top 4.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateAug 20

Description

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages5 packages

NVDapache/tomcat9.0.929.0.96+2
Mavenorg.apache.tomcat:tomcat-coyote9.0.929.0.96+2
CVEListV5apache_software_foundation/apache_tomcat11.0.0-M2311.0.0-M26+2
Debiantomcat10< 10.1.31-1+1

🔴Vulnerability Details

4
OSV
Apache Tomcat Request and/or response mix-up2024-11-18
OSV
CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat2024-11-18
GHSA
Apache Tomcat Request and/or response mix-up2024-11-18
CVEList
Apache Tomcat: Request/response mix-up with HTTP/22024-11-18

📋Vendor Advisories

3
Ubuntu
Tomcat vulnerabilities2025-08-20
Red Hat
tomcat: Apache Tomcat: Request/response mix-up with HTTP/22024-11-18
Debian
CVE-2024-52317: tomcat10 - Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect...2024
CVE-2024-52317 (MEDIUM CVSS 6.5) | Incorrect object re-cycling and re- | cvebase.io