Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7674

Опубликовано: 11 авг. 2017
Источник: debian
EPSS Низкий

Описание

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat9not-affectedpackage
tomcat8fixed8.5.16-1package
tomcat7fixed7.0.72-3package
tomcat7not-affectedwheezypackage

Примечания

  • Since 7.0.72-3, src:tomcat7 only builds the Servlet API

  • Fixed by: http://svn.apache.org/r1795814 (8.5.x)

  • Fixed by: http://svn.apache.org/r1795815 (8.0.x)

  • Fixed by: http://svn.apache.org/r1795816 (7.0.x)

  • https://bz.apache.org/bugzilla/show_bug.cgi?id=61101

EPSS

Процентиль: 88%
0.04091
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
почти 8 лет назад

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

CVSS3: 5.9
redhat
почти 8 лет назад

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

CVSS3: 4.3
nvd
почти 8 лет назад

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

CVSS3: 4.3
github
около 3 лет назад

Insufficient Verification of Data Authenticity in Apache Tomcat

fstec
почти 8 лет назад

Уязвимость фильтра CORS сервера приложений Apache Tomcat, позволяющая нарушителю осуществить заражение клиента и сервера при определенных обстоятельствах

EPSS

Процентиль: 88%
0.04091
Низкий