Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qhqv-q4xg-f6g7

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache Tomcat AJP Connector Information Leak

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

Пакеты

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 4.0.1, <= 4.0.6

Отсутствует

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 4.1.0, <= 4.1.36

Отсутствует

EPSS

Процентиль: 87%
0.03388
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 19 лет назад

The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body data" is used for a different request, possibly related to Java Servlet pages.

EPSS

Процентиль: 87%
0.03388
Низкий

Дефекты

CWE-200