Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj6c-prgj-gr3r

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

Ссылки

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.4

7.0.4

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 6.0.0, < 6.0.30

6.0.30

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 5.5.0, < 5.5.30

5.5.30

EPSS

Процентиль: 48%
0.00249
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

redhat
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

nvd
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write files outside of the intended working directory, as demonstrated using a directory traversal attack.

debian
больше 14 лет назад

Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running with ...

oracle-oval
около 14 лет назад

ELSA-2011-0791: tomcat6 security and bug fix update (MODERATE)

EPSS

Процентиль: 48%
0.00249
Низкий

Дефекты

CWE-22