Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the current request/response to the next.
Older, EOL versions may also be affected.


Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Project Subscriptions

Vendors Products
Accumulo Subscribe
Debian Linux Subscribe
Enterprise Linux Subscribe
Jboss Enterprise Web Server Subscribe
Jboss Fuse Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3617-1 tomcat9 security update
Debian DSA Debian DSA DSA-5521-1 tomcat10 security update
Debian DSA Debian DSA DSA-5522-1 tomcat9 security update
EUVD EUVD EUVD-2023-2737 Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.
Github GHSA Github GHSA GHSA-g8pj-r55q-5c2v Apache Tomcat Incomplete Cleanup vulnerability
Ubuntu USN Ubuntu USN USN-7106-1 Tomcat vulnerabilities
Ubuntu USN Ubuntu USN USN-7562-1 Tomcat vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 07 Aug 2025 11:15:00 +0000

Type Values Removed Values Added
Description Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue. Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Description Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue. Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fixes the issue.

Wed, 18 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache accumulo
CPEs cpe:2.3:a:apache:accumulo:-:*:*:*:*:*:*:*
Vendors & Products Apache accumulo
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-10-29T12:02:59.708Z

Reserved: 2023-09-14T12:11:26.550Z

Link: CVE-2023-42795

cve-icon Vulnrichment

Updated: 2024-08-02T19:30:24.387Z

cve-icon NVD

Status : Modified

Published: 2023-10-10T18:15:18.933

Modified: 2025-08-07T11:15:27.710

Link: CVE-2023-42795

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-10-10T00:00:00Z

Links: CVE-2023-42795 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses