{"id":"CVE-2023-34981","summary":"Apache Tomcat: AJP response header mix-up","details":"A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.","aliases":["BIT-tomcat-2023-34981","GHSA-mppv-79ch-vw6q"],"modified":"2026-08-12T03:30:14.595873942Z","published":"2023-06-21T10:26:16.916Z","database_specific":{"cna_assigner":"apache","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34981.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"11.0.0-M5"},{"last_affected":"11.0.0-M5"},{"introduced":"10.1.8"},{"last_affected":"10.1.8"},{"introduced":"9.0.74"},{"last_affected":"9.0.74"},{"introduced":"8.5.88"},{"last_affected":"8.5.88"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34981.json"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/j1ksjh9m9gx1q60rtk1sbzmxhvj5h5qz"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34981"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20230714-0003/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"e035e211705c7ec7a2ecf666f4a1fdf0965e9977"},{"last_affected":"06977fbea3c82c3d29e544203983dd3b49a632f1"}],"database_specific":{"cpe":["cpe:2.3:a:apache:tomcat:8.5.88:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:9.0.74:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:10.1.8:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.5.88"},{"last_affected":"8.5.88"},{"introduced":"9.0.74"},{"last_affected":"9.0.74"},{"introduced":"10.1.8"},{"last_affected":"10.1.8"},{"introduced":"11.0.0-milestone5"},{"last_affected":"11.0.0-milestone5"}],"source":"CPE_STRING"}}],"versions":["10.1.8","11.0.0-milestone5","8.5.88","9.0.74"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-34981.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}