UNKNOWN Maven

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

GHSA-3p5r-7cw3-2m67 · CVE-2013-2071

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

Ready to move

Start Securing

Free, no credit card | First findings in minutes