Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | tomcat | 11.0.0-M1, 10.1.0-M7, 9.0.83 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | tomcat | cert_advisory | 90% |
| atlassian | jira | cert_advisory | 90% |
| atlassian | confluence | cert_advisory | 90% |
| atlassian | crucible | cert_advisory | 90% |
| atlassian | bamboo | cert_advisory | 90% |
Updated severity to CRITICAL, added affected version 9.0.81, and noted no patch available.
Updated severity to LOW, added affected version 9.0.82, and marked exploit as available and actively exploited.
Initial creation