PT-2024-8688 · Apache+1 · Apache Tomcat+1

·

CVE-2024-52318

·

Published

2024-11-11

·

Updated

2025-05-15

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.96 through 11.0.0 Apache Tomcat version 10.1.31
Description The issue is related to incorrect object recycling and reuse in Apache Tomcat, which can lead to a cross-site scripting (XSS) attack. This occurs because pooled JSP tags are not released after use, causing some tags' output not to be escaped as expected, resulting in unescaped output that could lead to XSS.
Recommendations For Apache Tomcat version 9.0.96, upgrade to version 9.0.97 or later. For Apache Tomcat version 10.1.31, upgrade to version 10.1.33 or later. For Apache Tomcat version 11.0.0, upgrade to version 11.0.1 or later.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1726
ALT-PU-2025-2379
BDU:2024-10290
BIT-TOMCAT-2024-52318
CVE-2024-52318
GHSA-F632-9449-3J4W
MGASA-2024-0379
OESA-2024-2460
OESA-2024-2461
OESA-2024-2462
OESA-2024-2463
OESA-2024-2464

Affected Products

Alt Linux
Apache Tomcat