Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 262
GHSA-j788-fx57-99wp
Cross-site scripting in Apache Tomcat
GHSA-w227-xcfx-3pj8
Exposure of Sensitive Information in Apache Tomcat
GHSA-5cw4-ggx9-36vg
Apache Tomcat Denial of Service via Malformed Request Headers
GHSA-7g59-hm8v-cwmc
Apache Tomcat information disclosure vulnerability
GHSA-5jpg-mjvg-hfhp
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
GHSA-m7xj-ccqc-p4g2
Apache Tomcat Directory Traversal vulnerability
GHSA-m8h8-6rvg-f4mg
Apache Tomcat Path Traversal Vulnerability
GHSA-f98p-9pp6-7q6c
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-q74x-qqhr-f8rx
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-qjw9-54p2-cgcx
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-j788-fx57-99wp Cross-site scripting in Apache Tomcat | 37% Средний | почти 4 года назад | ||
GHSA-w227-xcfx-3pj8 Exposure of Sensitive Information in Apache Tomcat | 84% Высокий | почти 4 года назад | ||
GHSA-5cw4-ggx9-36vg Apache Tomcat Denial of Service via Malformed Request Headers | 14% Средний | почти 4 года назад | ||
GHSA-7g59-hm8v-cwmc Apache Tomcat information disclosure vulnerability | 8% Низкий | почти 4 года назад | ||
GHSA-5jpg-mjvg-hfhp Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve. | 4% Низкий | почти 4 года назад | ||
GHSA-m7xj-ccqc-p4g2 Apache Tomcat Directory Traversal vulnerability | 93% Критический | почти 4 года назад | ||
GHSA-m8h8-6rvg-f4mg Apache Tomcat Path Traversal Vulnerability | 89% Высокий | почти 4 года назад | ||
GHSA-f98p-9pp6-7q6c Apache Tomcat Cross-site scripting (XSS) vulnerability | 59% Средний | почти 4 года назад | ||
GHSA-q74x-qqhr-f8rx Apache Tomcat Cross-site scripting (XSS) vulnerability | 38% Средний | почти 4 года назад | ||
GHSA-qjw9-54p2-cgcx The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 4% Низкий | почти 4 года назад |
Уязвимостей на страницу