Two vulnerabilities were discovered in the Tomcat servlet and JSP engine,
which could result in HTTP request smuggling, bypass of logout
restrictions or authentications using variations of a valid user name.
For the stable distribution (buster), these problems have been fixed in
We recommend that you upgrade your tomcat9 packages.