Логотип exploitDog
product: "tomcat"
Консоль
Логотип exploitDog

exploitDog

product: "tomcat"
Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

8.08.5910.010.111.02014201520162017201820192020202120222023202420252026

Недавние уязвимости Tomcat

Количество 1 155

redhat логотип

CVE-2023-41080

около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-q3mw-pvr8-9ggc

около 2 лет назад

Apache Tomcat Open Redirect vulnerability

CVSS3: 6.1
EPSS: Средний
nvd логотип

CVE-2023-41080

около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
EPSS: Средний
debian логотип

CVE-2023-41080

около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in F ...

CVSS3: 6.1
EPSS: Средний
ubuntu логотип

CVE-2023-41080

около 2 лет назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
EPSS: Средний
github логотип

GHSA-cx6h-86xw-9x34

около 2 лет назад

Apache Tomcat - Fix for CVE-2023-24998 was incomplete

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mppv-79ch-vw6q

около 2 лет назад

Apache Tomcat vulnerable to information leak

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-34981

около 2 лет назад

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-34981

около 2 лет назад

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-34981

около 2 лет назад

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
11%
Средний
около 2 лет назад
github логотип
GHSA-q3mw-pvr8-9ggc

Apache Tomcat Open Redirect vulnerability

CVSS3: 6.1
11%
Средний
около 2 лет назад
nvd логотип
CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
11%
Средний
около 2 лет назад
debian логотип
CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in F ...

CVSS3: 6.1
11%
Средний
около 2 лет назад
ubuntu логотип
CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
11%
Средний
около 2 лет назад
github логотип
GHSA-cx6h-86xw-9x34

Apache Tomcat - Fix for CVE-2023-24998 was incomplete

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-mppv-79ch-vw6q

Apache Tomcat vulnerable to information leak

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1 ...

CVSS3: 7.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-34981

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.

CVSS3: 7.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться