Описание
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/xenial | needed | |
esm-infra-legacy/trusty | needed | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | ignored | end of standard support, was needed |
cosmic | ignored | end of life |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/bionic | needed | |
esm-apps/xenial | needed | |
esm-infra-legacy/trusty | not-affected | 7.0.52-1ubuntu0.16 |
esm-infra/focal | DNE | |
focal | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 8.5.39-1ubuntu1~18.04.1 |
cosmic | released | 8.5.39-1ubuntu1~18.10 |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-apps/bionic | released | 8.5.39-1ubuntu1~18.04.1 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
esm-infra/xenial | not-affected | 8.0.32-1ubuntu1.8 |
focal | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
cosmic | DNE | |
devel | DNE | |
disco | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | DNE | |
focal | DNE | |
groovy | DNE | |
hirsute | DNE |
Показывать по
4.3 Medium
CVSS2
4.3 Medium
CVSS3
Связанные уязвимости
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, ...
4.3 Medium
CVSS2
4.3 Medium
CVSS3