CVE-2024-52318
published 2024-11-18CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to…
PriorityP432medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.68%
74.3th percentile
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| apache_software_foundation | apache_tomcat | — | — |
| debian | tomcat10 | < tomcat10 10.1.33-1 (forky) | tomcat10 10.1.33-1 (forky) |
| debian | tomcat9 | < tomcat10 10.1.33-1 (forky) | tomcat10 10.1.33-1 (forky) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tomcat - XSS in generated JSPs
osv·2024-11-18
CVE-2024-52318 [MEDIUM] Apache Tomcat - XSS in generated JSPs
Apache Tomcat - XSS in generated JSPs
# Description:
The fix for improvement 69333 caused pooled JSP tags not to be released after use which in turn could cause output of some tags not to escaped as expected. This unescaped output could lead to XSS.
# Versions Affected:
- Apache Tomcat 11.0.0
- Apache Tomcat 10.1.31
- Apache Tomcat 9.0.96
# Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.1 or later
- Upgrade to Apache Tomcat 10.1.33 or later
Note: 10.1.32 was not released
- Upgrade to Apache Tomcat 9.0.97 or later
GHSA
Apache Tomcat - XSS in generated JSPs
ghsa·2024-11-18
CVE-2024-52318 [MEDIUM] CWE-326 Apache Tomcat - XSS in generated JSPs
Apache Tomcat - XSS in generated JSPs
# Description:
The fix for improvement 69333 caused pooled JSP tags not to be released after use which in turn could cause output of some tags not to escaped as expected. This unescaped output could lead to XSS.
# Versions Affected:
- Apache Tomcat 11.0.0
- Apache Tomcat 10.1.31
- Apache Tomcat 9.0.96
# Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.1 or later
- Upgrade to Apache Tomcat 10.1.33 or later
Note: 10.1.32 was not released
- Upgrade to Apache Tomcat 9.0.97 or later
OSV
CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat
osv·2024-11-18·CVSS 6.1
CVE-2024-52318 [MEDIUM] CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
Red Hat
tomcat: incorrect JSP tag recycling leads to XSS
vendor_redhat·2024-11-18·CVSS 6.1
CVE-2024-52318 [MEDIUM] CWE-79 tomcat: incorrect JSP tag recycling leads to XSS
tomcat: incorrect JSP tag recycling leads to XSS
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
A flaw was found in Apache Tomcat. Pooled JavaServer Pages (JSP) tags are not released after use, which could cause the output of some tags not to escape as expected. This unescaped output could leave the application vulnerable to Cross-site scripting (XSS).
Statement: Per the upstream advisory, this vulnerability is limited to Tomcat versions 9.0.96, 10.1.31, and 11.0.0. No Red Hat products are vulnerable to this flaw.
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: pki-deps:10.6/pki-servlet-engin
Debian
CVE-2024-52318: tomcat10 - Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue...
vendor_debian·2024·CVSS 6.1
CVE-2024-52318 [MEDIUM] CVE-2024-52318: tomcat10 - Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue...
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
Scope: local
bookworm: resolved
forky: resolved (fixed in 10.1.33-1)
sid: resolved (fixed in 10.1.33-1)
trixie: resolved (fixed in 10.1.33-1)
No detection rules found.
No public exploits indexed.
2024-11-18
Published