Количество 1 429
Количество 1 429
GHSA-h468-7pvh-8vr8
Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor
GHSA-h3gc-qfqq-6h8f
Apache Tomcat - DoS in multipart upload
GHSA-h2fw-rfh5-95r3
Apache Tomcat - CGI security constraint bypass
GHSA-gx5v-xp9w-j4cg
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
GHSA-gqp3-2cvr-x8m3
Apache Tomcat Improper Resource Shutdown or Release vulnerability
GHSA-ggx9-4728-588r
Apache Tomcat Directory Traversal vulnerability
GHSA-g8pj-r55q-5c2v
Apache Tomcat Incomplete Cleanup vulnerability
GHSA-g77g-vjjm-x83j
Apache Tomcat Example Application CSRF and XSS Vulnerabilities
GHSA-fv25-8xcx-gqjc
Apache Tomcat - WebSocket authentication header exposure
GHSA-fpj8-gq4v-p354
Apache Tomcat - Client certificate verification bypass
GHSA-fj6c-prgj-gr3r
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
GHSA-ff77-26x5-69cr
Apache Tomcat Rewrite rule bypass
GHSA-fccv-jmmp-qg76
Apache Tomcat Improper Input Validation vulnerability
GHSA-f98p-9pp6-7q6c
Apache Tomcat Cross-site scripting (XSS) vulnerability
GHSA-f632-9449-3j4w
Apache Tomcat - XSS in generated JSPs
GHSA-f4qf-m5gf-8jm8
Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information
GHSA-f436-gr4m-qq5w
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages.
GHSA-f2gq-p6qv-ccw4
Tomcat Vulnerable to Web Cache Poisoning
GHSA-cxg2-49rq-8gcr
Apache Tomcat does not properly handle an invalid Transfer-Encoding header
GHSA-cwxf-7cw2-7r32
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h468-7pvh-8vr8 Apache Tomcat: Padding Oracle vulnerability in EncryptInterceptor | CVSS3: 7.5 | 6% Низкий | 4 месяца назад | |
GHSA-h3gc-qfqq-6h8f Apache Tomcat - DoS in multipart upload | CVSS3: 7.5 | 56% Средний | около 1 года назад | |
GHSA-h2fw-rfh5-95r3 Apache Tomcat - CGI security constraint bypass | 3% Низкий | около 1 года назад | ||
GHSA-gx5v-xp9w-j4cg Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
GHSA-gqp3-2cvr-x8m3 Apache Tomcat Improper Resource Shutdown or Release vulnerability | CVSS3: 7.5 | 4% Низкий | 12 месяцев назад | |
GHSA-ggx9-4728-588r Apache Tomcat Directory Traversal vulnerability | 10% Низкий | около 4 лет назад | ||
GHSA-g8pj-r55q-5c2v Apache Tomcat Incomplete Cleanup vulnerability | CVSS3: 5.3 | 2% Низкий | почти 3 года назад | |
GHSA-g77g-vjjm-x83j Apache Tomcat Example Application CSRF and XSS Vulnerabilities | 2% Низкий | около 4 лет назад | ||
GHSA-fv25-8xcx-gqjc Apache Tomcat - WebSocket authentication header exposure | CVSS3: 7.3 | 1% Низкий | 3 месяца назад | |
GHSA-fpj8-gq4v-p354 Apache Tomcat - Client certificate verification bypass | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад | |
GHSA-fj6c-prgj-gr3r Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat | 1% Низкий | около 4 лет назад | ||
GHSA-ff77-26x5-69cr Apache Tomcat Rewrite rule bypass | 4% Низкий | больше 1 года назад | ||
GHSA-fccv-jmmp-qg76 Apache Tomcat Improper Input Validation vulnerability | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
GHSA-f98p-9pp6-7q6c Apache Tomcat Cross-site scripting (XSS) vulnerability | 10% Низкий | около 4 лет назад | ||
GHSA-f632-9449-3j4w Apache Tomcat - XSS in generated JSPs | CVSS3: 6.1 | 2% Низкий | больше 1 года назад | |
GHSA-f4qf-m5gf-8jm8 Apache Tomcat vulnerable to Generation of Error Message Containing Sensitive Information | CVSS3: 5.3 | 14% Средний | больше 2 лет назад | |
GHSA-f436-gr4m-qq5w The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in error messages. | 41% Средний | больше 4 лет назад | ||
GHSA-f2gq-p6qv-ccw4 Tomcat Vulnerable to Web Cache Poisoning | 30% Средний | около 4 лет назад | ||
GHSA-cxg2-49rq-8gcr Apache Tomcat does not properly handle an invalid Transfer-Encoding header | 55% Средний | около 4 лет назад | ||
GHSA-cwxf-7cw2-7r32 Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue. | CVSS3: 9.1 | 1% Низкий | 17 дней назад |
Уязвимостей на страницу