Количество 1 427
Количество 1 427
GHSA-jrcp-c39h-r29x
Improper Neutralization of Input During Web Page Generation in Apache Tomcat
GHSA-jpqr-vh55-xqxf
Apache Tomcat Buffer Over-Read
GHSA-jmvv-524f-hj5j
Improper Handling of Exceptional Conditions in Apache Tomcat
GHSA-jm7m-8jh6-29hp
Apache Tomcat Incomplete Cleanup vulnerability
GHSA-jjxj-xvcp-cxv8
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
GHSA-jjpq-gp5q-8q6w
Cross-site scripting in Apache Tomcat
GHSA-jgm2-m5cg-f66g
Authentication Bypass in Apache Tomcat
GHSA-jc7p-5r39-9477
Improper Input Validation in Apache Tomcat
GHSA-j788-fx57-99wp
Cross-site scripting in Apache Tomcat
GHSA-j448-j653-r3vj
Apache Tomcat is vulnerable to HTTP request-smuggling
GHSA-hjfh-7c4v-7q8h
Improper Authentication in Apache Tomcat
GHSA-hhjg-g8xq-hhr3
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
GHSA-hgrr-935x-pq79
Apache Tomcat Vulnerable to Improper Resource Shutdown or Release
GHSA-hffm-fqv4-w27r
Improper Authentication in Apache Tomcat
GHSA-hcjr-322h-429r
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue.
GHSA-hc39-rjwp-qffq
Apache Tomcat XSS Vulnerabilities in Examples Web Application
GHSA-h792-v28v-ppgr
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
GHSA-h6fc-48rj-7qqh
Apache Tomcat - Digest authenticator will authenticate any unknown user
GHSA-h6c8-x5r3-pm88
Apache Tomcat Unrestricted file upload vulnerability
GHSA-h6c8-rg87-f3pc
Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-jrcp-c39h-r29x Improper Neutralization of Input During Web Page Generation in Apache Tomcat | CVSS3: 8.1 | 11% Средний | около 4 лет назад | |
GHSA-jpqr-vh55-xqxf Apache Tomcat Buffer Over-Read | 8% Низкий | около 4 лет назад | ||
GHSA-jmvv-524f-hj5j Improper Handling of Exceptional Conditions in Apache Tomcat | CVSS3: 7.5 | 17% Средний | около 4 лет назад | |
GHSA-jm7m-8jh6-29hp Apache Tomcat Incomplete Cleanup vulnerability | CVSS3: 5.9 | 2% Низкий | почти 3 года назад | |
GHSA-jjxj-xvcp-cxv8 Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet. | 12% Средний | больше 4 лет назад | ||
GHSA-jjpq-gp5q-8q6w Cross-site scripting in Apache Tomcat | CVSS3: 6.1 | 46% Средний | около 7 лет назад | |
GHSA-jgm2-m5cg-f66g Authentication Bypass in Apache Tomcat | 12% Средний | около 4 лет назад | ||
GHSA-jc7p-5r39-9477 Improper Input Validation in Apache Tomcat | CVSS3: 7.1 | 40% Средний | около 4 лет назад | |
GHSA-j788-fx57-99wp Cross-site scripting in Apache Tomcat | 9% Низкий | около 4 лет назад | ||
GHSA-j448-j653-r3vj Apache Tomcat is vulnerable to HTTP request-smuggling | 17% Средний | около 4 лет назад | ||
GHSA-hjfh-7c4v-7q8h Improper Authentication in Apache Tomcat | 8% Низкий | около 4 лет назад | ||
GHSA-hhjg-g8xq-hhr3 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat | CVSS3: 4.2 | 1% Низкий | около 4 лет назад | |
GHSA-hgrr-935x-pq79 Apache Tomcat Vulnerable to Improper Resource Shutdown or Release | CVSS3: 5.3 | 1% Низкий | 9 месяцев назад | |
GHSA-hffm-fqv4-w27r Improper Authentication in Apache Tomcat | 7% Низкий | около 4 лет назад | ||
GHSA-hcjr-322h-429r Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120, which fix the issue. | CVSS3: 9.1 | 0% Низкий | 17 дней назад | |
GHSA-hc39-rjwp-qffq Apache Tomcat XSS Vulnerabilities in Examples Web Application | 77% Высокий | около 4 лет назад | ||
GHSA-h792-v28v-ppgr Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue. | CVSS3: 7.3 | 1% Низкий | около 1 месяца назад | |
GHSA-h6fc-48rj-7qqh Apache Tomcat - Digest authenticator will authenticate any unknown user | CVSS3: 9.8 | 1% Низкий | 3 месяца назад | |
GHSA-h6c8-x5r3-pm88 Apache Tomcat Unrestricted file upload vulnerability | 14% Средний | около 4 лет назад | ||
GHSA-h6c8-rg87-f3pc Apache Tomcat HTTP BIO Connector Error Discloses Information From Different Requests to Remote Users | 9% Низкий | около 4 лет назад |
Уязвимостей на страницу