CVE-2024-52317
MEDIUM 6.5EPSS 2.1%
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 2.10% chance of exploitation in the next 30 days, 80th percentile
- Published
- 2024-11-18
- Updated
- 2025-01-24
Proof-of-concept exploits (1)
- TAM-K592/CVE-2024-523173★ · 2024-11-21