Количество 1 429
Количество 1 429
GHSA-r84p-88g2-2vx2
Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption
GHSA-qhqv-q4xg-f6g7
Apache Tomcat AJP Connector Information Leak
GHSA-pxcx-cxq8-4mmw
Uncontrolled Resource Consumption in Apache Tomcat
GHSA-pqr5-9v2j-44xg
Apache Tomcat DoS via Malicious Get Request
GHSA-mgp5-rv84-w37q
Apache Tomcat has an Improper Input Validation vulnerability
GHSA-h3ch-5pp2-vh6w
Improper socket reuse in Apache Tomcat
GHSA-g7cf-wg27-qw87
Jenkins secure flag not set on session cookies
GHSA-cx6h-86xw-9x34
Apache Tomcat - Fix for CVE-2023-24998 was incomplete
GHSA-c7fc-mp9g-99j3
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group.
GHSA-95jq-rwvf-vjx4
Apache Tomcat: CLIENT_CERT authentication does not fail as expected
GHSA-7mg3-pr99-8rh7
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
GHSA-7jqf-v358-p8g7
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
GHSA-7f6w-fhmr-j8hq
Jenkins HttpOnly flag not Set for session cookies
GHSA-59g9-7gfx-c72p
Infinite loop in Tomcat due to parsing error
GHSA-4prh-gqw8-rgh5
Apache Tomcat Directory Traversal
GHSA-46j3-r4pj-4835
The host name verification missing in Apache Tomcat
GHSA-3v4j-mhgf-pf6w
The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers.
GHSA-2rvv-w9r2-rg7m
Information Disclosure in Apache Tomcat
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
CVE-2026-29145
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-r84p-88g2-2vx2 Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption | CVSS3: 7.5 | 73% Высокий | около 4 лет назад | |
GHSA-qhqv-q4xg-f6g7 Apache Tomcat AJP Connector Information Leak | 7% Низкий | больше 4 лет назад | ||
GHSA-pxcx-cxq8-4mmw Uncontrolled Resource Consumption in Apache Tomcat | 20% Средний | около 4 лет назад | ||
GHSA-pqr5-9v2j-44xg Apache Tomcat DoS via Malicious Get Request | 10% Низкий | больше 4 лет назад | ||
GHSA-mgp5-rv84-w37q Apache Tomcat has an Improper Input Validation vulnerability | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-h3ch-5pp2-vh6w Improper socket reuse in Apache Tomcat | CVSS3: 8.6 | 8% Низкий | около 4 лет назад | |
GHSA-g7cf-wg27-qw87 Jenkins secure flag not set on session cookies | CVSS3: 5.3 | 3% Низкий | около 4 лет назад | |
GHSA-cx6h-86xw-9x34 Apache Tomcat - Fix for CVE-2023-24998 was incomplete | CVSS3: 7.5 | 50% Средний | около 3 лет назад | |
GHSA-c7fc-mp9g-99j3 The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by leveraging membership in the tomcat group. | CVSS3: 7.8 | 4% Низкий | около 4 лет назад | |
GHSA-95jq-rwvf-vjx4 Apache Tomcat: CLIENT_CERT authentication does not fail as expected | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
GHSA-7mg3-pr99-8rh7 native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application. | 7% Низкий | около 4 лет назад | ||
GHSA-7jqf-v358-p8g7 Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability | CVSS3: 8.6 | 2% Низкий | больше 1 года назад | |
GHSA-7f6w-fhmr-j8hq Jenkins HttpOnly flag not Set for session cookies | CVSS3: 5.3 | 3% Низкий | около 4 лет назад | |
GHSA-59g9-7gfx-c72p Infinite loop in Tomcat due to parsing error | CVSS3: 7.5 | 7% Низкий | почти 5 лет назад | |
GHSA-4prh-gqw8-rgh5 Apache Tomcat Directory Traversal | 91% Критический | около 4 лет назад | ||
GHSA-46j3-r4pj-4835 The host name verification missing in Apache Tomcat | CVSS3: 7.5 | 21% Средний | почти 8 лет назад | |
GHSA-3v4j-mhgf-pf6w The JK Connector (aka mod_jk) 1.2.0 through 1.2.26 in Apache Tomcat allows remote attackers to obtain sensitive information via an arbitrary request from an HTTP client, in opportunistic circumstances involving (1) a request from a different client that included a Content-Length header but no POST data or (2) a rapid series of requests, related to noncompliance with the AJP protocol's requirements for requests containing Content-Length headers. | 7% Низкий | около 4 лет назад | ||
GHSA-2rvv-w9r2-rg7m Information Disclosure in Apache Tomcat | CVSS3: 5.9 | 23% Средний | около 5 лет назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | CVSS3: 9.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-29145 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39, from 1.3.0 through 1.3.6, from 2.0.0 through 2.0.13. Users are recommended to upgrade to version Tomcat Native 1.3.7 or 2.0.14 and Tomcat 11.0.20, 10.1.53 and 9.0.116, which fix the issue. | CVSS3: 5.9 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу