DEBIAN-CVE-2024-52317

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2024-52317
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-52317.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-52317
Upstream
Published
2024-11-18T12:15:18Z
Modified
2025-09-25T04:19:05.728662Z
Summary
[none]
Details

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.

References

Affected packages

Debian:13 / tomcat10

Package

Name
tomcat10
Purl
pkg:deb/debian/tomcat10?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.31-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / tomcat10

Package

Name
tomcat10
Purl
pkg:deb/debian/tomcat10?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1.31-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}