Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 155
GHSA-cw54-59pw-4g8c
Apache Tomcat Improper Access Control vulnerability
GHSA-v35g-wxj7-gxp3
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
GHSA-h6c8-x5r3-pm88
Apache Tomcat Unrestricted file upload vulnerability
GHSA-5xvw-jhvw-hvp2
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to gain root privileges via a setgid program in the Catalina directory, as demonstrated by /etc/tomcat8/Catalina/attack.
GHSA-3mjp-p938-4329
Apache Tomcat vulnerable to SecurityManager bypass
GHSA-2rvf-329f-p99g
System Property Disclosure in Apache Tomcat
GHSA-wxcp-f2c8-x6xv
Observable Discrepancy in Apache Tomcat
GHSA-q6x7-f33r-3wxx
Incorrect Authorization in Apache Tomcat
GHSA-4v3g-g84w-hv7r
Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
GHSA-r84p-88g2-2vx2
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-cw54-59pw-4g8c Apache Tomcat Improper Access Control vulnerability | CVSS3: 9.8 | 94% Критический | больше 3 лет назад | |
GHSA-v35g-wxj7-gxp3 Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | 14% Средний | больше 3 лет назад | ||
GHSA-h6c8-x5r3-pm88 Apache Tomcat Unrestricted file upload vulnerability | 8% Низкий | больше 3 лет назад | ||
GHSA-5xvw-jhvw-hvp2 The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to gain root privileges via a setgid program in the Catalina directory, as demonstrated by /etc/tomcat8/Catalina/attack. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjp-p938-4329 Apache Tomcat vulnerable to SecurityManager bypass | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2rvf-329f-p99g System Property Disclosure in Apache Tomcat | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-wxcp-f2c8-x6xv Observable Discrepancy in Apache Tomcat | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
GHSA-q6x7-f33r-3wxx Incorrect Authorization in Apache Tomcat | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-4v3g-g84w-hv7r Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat | CVSS3: 9.1 | 1% Низкий | больше 3 лет назад | |
GHSA-r84p-88g2-2vx2 Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption | CVSS3: 7.5 | 65% Средний | больше 3 лет назад |
Уязвимостей на страницу