-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | maven | >= 9.0.92, < 9.0.96 | 9.0.96 |
| org.apache.tomcat:tomcat-coyote | maven | >= 9.0.92, < 9.0.96 | 9.0.96 |
| org.apache.tomcat.embed:tomcat-embed-core | maven | >= 10.1.27, < 10.1.31 | 10.1.31 |
| org.apache.tomcat.embed:tomcat-embed-core | maven | >= 11.0.0-M23, < 11.0.0 | 11.0.0 |
| org.apache.tomcat:tomcat-coyote | maven | >= 10.1.27, < 10.1.31 | 10.1.31 |
| org.apache.tomcat:tomcat-coyote | maven | >= 11.0.0-M23, < 11.0.0 | 11.0.0 |
The analysis is based on the changes observed in the provided patches, focusing on functions related to stream handling and recycling. The key functions identified are directly related to the changes made to fix the vulnerability.
Ongoing coverage of React2Shell