Tomcat — контейнер сервлетов с открытым исходным кодом
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 466
SUSE-SU-2020:14334-1
Security update for tomcat6
ELSA-2020-0912
ELSA-2020-0912: tomcat6 security update (IMPORTANT)
ELSA-2020-0855
ELSA-2020-0855: tomcat security update (IMPORTANT)
SUSE-SU-2020:0725-1
Security update for tomcat
GHSA-767j-jfh2-jvrc
Potential HTTP request smuggling in Apache Tomcat
GHSA-qxf4-chvg-4r8r
Potential HTTP request smuggling in Apache Tomcat
CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, alon
CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when tr ...
CVE-2020-1935
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
CVE-2020-1935
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
SUSE-SU-2020:14334-1 Security update for tomcat6 | 99% Критический | больше 6 лет назад | ||
ELSA-2020-0912 ELSA-2020-0912: tomcat6 security update (IMPORTANT) | 99% Критический | больше 6 лет назад | ||
ELSA-2020-0855 ELSA-2020-0855: tomcat security update (IMPORTANT) | 99% Критический | больше 6 лет назад | ||
SUSE-SU-2020:0725-1 Security update for tomcat | 99% Критический | больше 6 лет назад | ||
GHSA-767j-jfh2-jvrc Potential HTTP request smuggling in Apache Tomcat | CVSS3: 4.8 | 9% Низкий | больше 6 лет назад | |
GHSA-qxf4-chvg-4r8r Potential HTTP request smuggling in Apache Tomcat | CVSS3: 4.8 | 9% Низкий | больше 6 лет назад | |
CVE-2020-1938 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, alon | CVSS3: 9.8 | 99% Критический | больше 6 лет назад | |
CVE-2020-1938 When using the Apache JServ Protocol (AJP), care must be taken when tr ... | CVSS3: 9.8 | 99% Критический | больше 6 лет назад | |
CVE-2020-1935 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely. | CVSS3: 4.8 | 9% Низкий | больше 6 лет назад | |
CVE-2020-1935 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ... | CVSS3: 4.8 | 9% Низкий | больше 6 лет назад |
Уязвимостей на страницу