Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 533
GHSA-j788-fx57-99wp
Cross-site scripting in Apache Tomcat
GHSA-w227-xcfx-3pj8
Exposure of Sensitive Information in Apache Tomcat
GHSA-5cw4-ggx9-36vg
Apache Tomcat Denial of Service via Malformed Request Headers
GHSA-7g59-hm8v-cwmc
Apache Tomcat information disclosure vulnerability
GHSA-5jpg-mjvg-hfhp
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
GHSA-m7xj-ccqc-p4g2
Apache Tomcat Directory Traversal vulnerability
GHSA-m8h8-6rvg-f4mg
Apache Tomcat Path Traversal Vulnerability
GHSA-f98p-9pp6-7q6c
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-q74x-qqhr-f8rx
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-qjw9-54p2-cgcx
The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-j788-fx57-99wp Cross-site scripting in Apache Tomcat | 9% Низкий | больше 4 лет назад | ||
GHSA-w227-xcfx-3pj8 Exposure of Sensitive Information in Apache Tomcat | 94% Критический | больше 4 лет назад | ||
GHSA-5cw4-ggx9-36vg Apache Tomcat Denial of Service via Malformed Request Headers | 10% Средний | больше 4 лет назад | ||
GHSA-7g59-hm8v-cwmc Apache Tomcat information disclosure vulnerability | 4% Низкий | больше 4 лет назад | ||
GHSA-5jpg-mjvg-hfhp Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve. | 5% Низкий | больше 4 лет назад | ||
GHSA-m7xj-ccqc-p4g2 Apache Tomcat Directory Traversal vulnerability | 100% Критический | больше 4 лет назад | ||
GHSA-m8h8-6rvg-f4mg Apache Tomcat Path Traversal Vulnerability | 53% Средний | больше 4 лет назад | ||
GHSA-f98p-9pp6-7q6c Apache Tomcat Cross-site scripting (XSS) vulnerability | 10% Низкий | больше 4 лет назад | ||
GHSA-q74x-qqhr-f8rx Apache Tomcat Cross-site scripting (XSS) vulnerability | 76% Высокий | больше 4 лет назад | ||
GHSA-qjw9-54p2-cgcx The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 20% Средний | больше 4 лет назад |
Уязвимостей на страницу