Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jrcp-c39h-r29x

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Improper Neutralization of Input During Web Page Generation in Apache Tomcat

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

Ссылки

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

= 9.0.0.M1

9.0.0.M2

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 8.0.0.RC1, <= 8.0.30

8.0.31

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.65

7.0.66

EPSS

Процентиль: 97%
0.39277
Средний

8.1 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
redhat
больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
nvd
больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to CoyoteAdapter.java and Request.java.

CVSS3: 8.1
debian
больше 9 лет назад

Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x ...

fstec
больше 9 лет назад

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю получить доступ к веб-сессиям

EPSS

Процентиль: 97%
0.39277
Средний

8.1 High

CVSS3

Дефекты

CWE-79