https://seclists.org/oss-sec/2024/q4/104: CVE-2024-52317: Apache Tomcat: quest/sponse mix-up with HTTP/2
Published Nov 18, 2024
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.0-M23<=11.0.0-M26
Apache Tomcat>=10.1.27<=10.1.30
Apache Tomcat>=9.0.92<=9.0.95
Frequently Asked Questions
1
What is the severity of CVE-2024-52317?
The severity of CVE-2024-52317 is categorized as important.
2
What versions of Apache Tomcat are affected by CVE-2024-52317?
CVE-2024-52317 affects Apache Tomcat versions 11.0.0-M23 through 11.0.0-M26, 10.1.27 through 10.1.30, and 9.0.92 through 9.0.95.
3
What is the main issue described in CVE-2024-52317?
CVE-2024-52317 could lead to a request and/or response mix-up between users in Apache Tomcat.
4
How do I fix CVE-2024-52317?
To fix CVE-2024-52317, upgrade to a version of Apache Tomcat that is not affected by this vulnerability.
5
What are the implications of CVE-2024-52317?
The implications of CVE-2024-52317 include potential exposure of user data due to request and response mix-ups.