Description
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Remediation
References
Related Vulnerabilities
WordPress Plugin Bangla Sidebar Login Cross-Site Scripting (1.0)
MySQL CVE-2023-22112 Vulnerability (CVE-2023-22112)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cross-Site Scripting (2.3.1)
WordPress Plugin SecuPress Pro Security Bypass (1.4.12)
WordPress Plugin Slider Hero with Animation, Video Background Cross-Site Request Forgery (8.2.0)