Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4qf-m5gf-8jm8

Опубликовано: 19 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.

Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 9.0.0-M11, < 9.0.44

9.0.44

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.5.7, < 8.5.64

8.5.64

EPSS

Процентиль: 98%
0.65426
Средний

5.3 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

CVSS3: 5.3
redhat
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

CVSS3: 5.3
nvd
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.

CVSS3: 5.3
debian
больше 1 года назад

Generation of Error Message Containing Sensitive Information vulnerabi ...

suse-cvrf
больше 1 года назад

Security update for tomcat

EPSS

Процентиль: 98%
0.65426
Средний

5.3 Medium

CVSS3

Дефекты

CWE-209