Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv64-5gf8-9qq8

Опубликовано: 09 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 9.0.40, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.54

10.1.54

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.21

11.0.21

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 9.0.40, < 9.0.116

9.0.116

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.54

10.1.54

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.21

11.0.21

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.40, < 9.0.116

9.0.116

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.54

10.1.54

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.21

11.0.21

EPSS

Процентиль: 38%
0.00461
Низкий

7.5 High

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

CVSS3: 5.4
redhat
4 месяца назад

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

CVSS3: 7.5
nvd
4 месяца назад

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

CVSS3: 7.5
debian
4 месяца назад

Improper Encoding or Escaping of Output vulnerability in the JsonAcces ...

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатком механизма кодирования или экранирования выходных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 38%
0.00461
Низкий

7.5 High

CVSS3

Дефекты

CWE-116