#VU100587 Resource management error in Apache Tomcat - CVE-2024-52317
Published: November 18, 2024 / Updated: December 13, 2024
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources when handling HTTP/2 responses, which causes request and/or response mix-up between users. A remote non-authenticated attacker can send a series of HTTP/2 requests and gain access to sensitive information.