Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjfr-qf3p-3q25

Опубликовано: 17 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the server

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Ссылки

Пакеты

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.79

7.0.79

EPSS

Процентиль: 100%
0.9436
Критический

8.1 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 8 лет назад

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS3: 8.1
redhat
почти 8 лет назад

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS3: 8.1
nvd
почти 8 лет назад

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

CVSS3: 8.1
debian
почти 8 лет назад

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs e ...

oracle-oval
больше 7 лет назад

ELSA-2017-3081: tomcat security update (IMPORTANT)

EPSS

Процентиль: 100%
0.9436
Критический

8.1 High

CVSS3

Дефекты

CWE-434