CVE-2024-21733: Apache Tomcat
Medium severity, CVSS 5.3. EPSS: 14.3% chance of exploitation in the next 30 days.
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
Affected products
- Apache Tomcat: from 8.5.7, before 8.5.64 (fixed in 8.5.64); from 9.0.1, before 9.0.44 (fixed in 9.0.44); version 9.0.0 only
Published 2024-01-19. Last modified 2026-06-17.