Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m48-jxwx-76q7

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Authentication in Apache Tomcat

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

Ссылки

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 6.0.21, < 6.0.37

6.0.37

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.33

7.0.33

EPSS

Процентиль: 88%
0.04198
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
около 12 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

redhat
около 12 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

nvd
около 12 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.

debian
около 12 лет назад

java/org/apache/catalina/authenticator/FormAuthenticator.java in the f ...

oracle-oval
около 12 лет назад

ELSA-2013-0964: tomcat6 security update (MODERATE)

EPSS

Процентиль: 88%
0.04198
Низкий

Дефекты

CWE-287