Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 466
CVE-2023-46589
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 1 ...
CVE-2023-46589
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
CVE-2023-46589
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
BDU:2024-01300
Уязвимость сервера приложений Apache Tomcat, связанная с непоследовательной интерпретацией HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
SUSE-SU-2023:4492-1
Security update for nghttp2
ELSA-2023-6746
ELSA-2023-6746: nghttp2 security update (IMPORTANT)
RLSA-2023:6120
Moderate: nginx:1.22 security update
SUSE-SU-2023:4295-1
Security update for nodejs10
ELSA-2023-6120
ELSA-2023-6120: nginx:1.22 security update (MODERATE)
SUSE-SU-2023:4200-1
Security update for nghttp2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2023-46589 Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 1 ... | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
CVE-2023-46589 Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue. | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
CVE-2023-46589 Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue. | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
BDU:2024-01300 Уязвимость сервера приложений Apache Tomcat, связанная с непоследовательной интерпретацией HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность защищаемой информации | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
SUSE-SU-2023:4492-1 Security update for nghttp2 | 100% Критический | больше 2 лет назад | ||
ELSA-2023-6746 ELSA-2023-6746: nghttp2 security update (IMPORTANT) | 100% Критический | больше 2 лет назад | ||
RLSA-2023:6120 Moderate: nginx:1.22 security update | 100% Критический | больше 2 лет назад | ||
SUSE-SU-2023:4295-1 Security update for nodejs10 | 100% Критический | почти 3 года назад | ||
ELSA-2023-6120 ELSA-2023-6120: nginx:1.22 security update (MODERATE) | 100% Критический | почти 3 года назад | ||
SUSE-SU-2023:4200-1 Security update for nghttp2 | 100% Критический | почти 3 года назад |
Уязвимостей на страницу