Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w65j-cmqc-37p2

Опубликовано: 01 мая 2022
Источник: github
Github: Прошло ревью

Описание

JULI logging component in Apache Tomcat does not restrict certain permissions for web applications

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

Ссылки

Пакеты

Наименование

org.apache.tomcat:tomcat-juli

maven
Затронутые версииВерсия исправления

>= 5.5.9, <= 5.5.25

Отсутствует

Наименование

org.apache.tomcat:tomcat-juli

maven
Затронутые версииВерсия исправления

>= 6.0.0, <= 6.0.15

Отсутствует

EPSS

Процентиль: 94%
0.12423
Средний

Дефекты

CWE-284

Связанные уязвимости

ubuntu
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

redhat
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

nvd
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.

debian
больше 17 лет назад

The default catalina.policy in the JULI logging component in Apache To ...

oracle-oval
больше 17 лет назад

ELSA-2008-0042: Moderate: tomcat security update (MODERATE)

EPSS

Процентиль: 94%
0.12423
Средний

Дефекты

CWE-284