First published: Tue Jul 09 2024(Updated: )
Sam Shahsavar discovered that Apache Tomcat did not properly reject HTTP requests with an invalid Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libtomcat9-java | <9.0.58-1ubuntu0.1+esm1 | 9.0.58-1ubuntu0.1+esm1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/tomcat9 | <9.0.58-1ubuntu0.1+esm1 | 9.0.58-1ubuntu0.1+esm1 |
Ubuntu Ubuntu | =22.04 | |
All of | ||
ubuntu/libtomcat9-java | <9.0.31-1ubuntu0.5 | 9.0.31-1ubuntu0.5 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/tomcat9 | <9.0.31-1ubuntu0.5 | 9.0.31-1ubuntu0.5 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/libtomcat8-java | <8.5.39-1ubuntu1~18.04.3+esm1 | 8.5.39-1ubuntu1~18.04.3+esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/libtomcat9-java | <9.0.16-3ubuntu0.18.04.2+esm1 | 9.0.16-3ubuntu0.18.04.2+esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/tomcat8 | <8.5.39-1ubuntu1~18.04.3+esm1 | 8.5.39-1ubuntu1~18.04.3+esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/tomcat9 | <9.0.16-3ubuntu0.18.04.2+esm1 | 9.0.16-3ubuntu0.18.04.2+esm1 |
Ubuntu Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.