tomcat is vulnerable to Improper Input Validation
65
Medium Risk
tomcat does not fully enforce strict SNI checks for HTTP/2 requests that omit an authority. A client can send a no-authority HTTP/2 request and skip the intended host match. That can route the request to the wrong virtual host. The fix requires every HTTP/2 request to provide an authority.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled with strict SNI validation.
tomcat is vulnerable to Improper Input Validation in versions 9.0.115 - 9.0.120, 10.1.53 - 10.1.57 and 11.0.20 - 11.0.24.
Upgrade the org.apache.tomcat:tomcat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.