Description
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
Remediation
References
Related Vulnerabilities
PrestaShop Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-7491)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2367)
Oracle Database Server CVE-2014-6452 Vulnerability (CVE-2014-6452)
MediaWiki Uncontrolled Resource Consumption Vulnerability (CVE-2022-39194)