Description
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Remediation
References
Related Vulnerabilities
WordPress Plugin Login with Azure (Azure SSO) Cross-Site Scripting (1.4.4)
Joomla! Core 3.x.x Cross-Site Request Forgery (3.0.0 - 3.9.26)
Apache HTTP Server Other Vulnerability (CVE-1999-0045)
WebLogic CVE-2022-21386 Vulnerability (CVE-2022-21386)
WordPress Plugin Image Slider Unspecified Vulnerability (1.1.119)