Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x29-79gh-6v8q

Опубликовано: 29 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

EPSS

Процентиль: 29%
0.00368
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-390

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 1 месяца назад

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CVSS3: 3.7
redhat
около 1 месяца назад

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CVSS3: 9.1
nvd
около 1 месяца назад

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.

CVSS3: 9.1
debian
около 1 месяца назад

Detection of Error Condition Without Action vulnerability in Apache To ...

EPSS

Процентиль: 29%
0.00368
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-390