Skip to content

CVE: 2021-33037 found in tomcat-embed-core - Version: 9.0.36 [JAVA] #158

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageJAVA
VulnerabilityRequest Smuggling
Vulnerability descriptiontomcat-coyote is vulnerable request smuggling. Incorrect way of parsing of the HTTP transfer-encoding request header causes request smuggling when it is used with a reverse proxy and if the client declared it would only accept an HTTP/1.0 response.
CVE2021-33037
CVSS score5
Vulnerability present in version/s9.0.0.M1-9.0.47
Found library version/s9.0.36
Vulnerability fixed in version9.0.48
Library latest version11.0.9
FixApply the fixes below.

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions