|
|
| |
|
| |
tomcat: information disclosure
| Package(s): | tomcat |
CVE #(s): | CVE-2013-2071
|
| Created: | May 21, 2013 |
Updated: | July 2, 2013 |
| Description: |
From the Red Hat bugzilla:
An information disclosure flaw was found in the way asynchronous context implementation of Apache Tomcat, an Apache Servlet/JSP Engine, performed request information management in certain circumstances (formerly certain elements of a previous request might have been exposed to the current request). If an application used AsyncListeners that threw RuntimeExceptions, a remote attacker could use this flaw to possibly obtain sensitive information. |
| Alerts: |
|
( Log in to post comments)
|
|
|