Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12616

Опубликовано: 19 сент. 2017
Источник: debian

Описание

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat7fixed7.0.72-3package

Примечания

  • Since 7.0.72-3, src:tomcat7 only builds the Servlet API

  • https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.81

  • https://svn.apache.org/r1804729

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 5.3
redhat
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
nvd
почти 8 лет назад

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

CVSS3: 7.5
github
около 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

suse-cvrf
больше 7 лет назад

Security update for tomcat