Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p22x-g9px-3945

Опубликовано: 01 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Tomcat may reject request containing invalid Content-Length header

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

Пакеты

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 8.5.0, < 8.5.83

8.5.83

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.0-M1, < 9.0.68

9.0.68

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.0.0-M1, < 10.0.27

10.0.27

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.1

10.1.1

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 9.0.0-M1, < 9.0.68

9.0.68

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 10.0.0-M1, < 10.0.27

10.0.27

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.1

10.1.1

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-444

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

CVSS3: 4.8
redhat
больше 2 лет назад

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

CVSS3: 7.5
nvd
больше 2 лет назад

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.

CVSS3: 7.5
debian
больше 2 лет назад

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10. ...

suse-cvrf
больше 2 лет назад

Security update for tomcat

EPSS

Процентиль: 38%
0.00164
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-444