tomcat-embed-core is vulnerable to Improper Input Validation
65
Medium Risk
tomcat-embed-core does not fully enforce strict SNI checks for HTTP/2 requests that omit an authority. A client can send a no-authority HTTP/2 request and skip the intended host match. That can route the request to the wrong virtual host. The fix requires every HTTP/2 request to provide an authority.
You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled with strict SNI validation.
tomcat-embed-core is vulnerable to Improper Input Validation in versions 9.0.115 - 9.0.120, 10.1.53 - 10.1.57 and 11.0.20 - 11.0.24.
Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.