Attack Surface Management Solutions | Sn1perSecurity LLC
Our security research team recently discovered a critical “0day” vulnerability which was assigned CVE-2024-21733. The vulnerability was discovered by xer0dayz from Sn1perSecurity LLC and allows attackers to force a victim’s browser to de-synchronize its connection with websites hosted on top of Apache Tomcat, causing sensitive data to be smuggled from the server and/or client connections. In some cases, this can leak sensitive data such as clear-text credentials.
Severity: CRITICAL | Exploit Available: Yes | Exploitability: Easy | Remotely Exploitable: Yes
Confused about the difference between Sn1per Professional and Sn1per Enterprise? We’ve got you covered. In this blog post, we’ll dive into the key distinctions to help you make an informed decision.