Description
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
Remediation
References
http://tomcat.apache.org/security-6.html
http://tomcat.apache.org/security-7.html
http://www.debian.org/security/2012/dsa-2401
Related Vulnerabilities
CVE-2018-1297 Vulnerability in maven package org.apache.jmeter:apachejmeter
CVE-2021-32013 Vulnerability in npm package xlsx
CVE-2023-34238 Vulnerability in npm package gatsby-cli
CVE-2023-25762 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-build-step
CVE-2020-8203 Vulnerability in maven package org.fujion.webjars:lodash