Количество 1 429
Количество 1 429
GHSA-6v52-mj5r-7j2m
Apache Tomcat Race Condition vulnerability
GHSA-6qr6-x7jm-x2q6
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
GHSA-6m48-jxwx-76q7
Improper Authentication in Apache Tomcat
GHSA-6j8f-66vh-39mj
Apache Tomcat Mishandles Character Sequence in Cookies
GHSA-6j88-6whg-x687
Cross-site Scripting in Apache Tomcat
GHSA-6gjj-c5mj-4cvp
Improper Input Validation in Apache Tomcat
GHSA-6cr4-7c7p-p3xv
Use of Hard-coded Cryptographic Key in Apache Tomcat
GHSA-69r9-qgr7-g2wj
Apache Tomcat Missing Encryption of Sensitive Data vulnerability
GHSA-69cc-cv78-qc8g
Apache Tomcat: Configured cipher preference order not preserved
GHSA-698c-2x4j-g9gq
Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
GHSA-68g5-8q7f-m384
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
GHSA-653p-vg55-5652
Apache Tomcat Uncontrolled Resource Consumption vulnerability
GHSA-5xvw-jhvw-hvp2
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to gain root privileges via a setgid program in the Catalina directory, as demonstrated by /etc/tomcat8/Catalina/attack.
GHSA-5x5f-9r6q-q7mh
Apache Tomcat Sensitive Information Disclosure
GHSA-5v3h-fjv2-54fg
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
GHSA-5mp6-jrq3-r938
Apache Tomcat: LockOutRealm treats user names as case-sensitive
GHSA-5m62-pw8w-7w9f
Apache Tomcat - Security constraints not correctly applied
GHSA-5jpg-mjvg-hfhp
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
GHSA-5j33-cvvr-w245
Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
GHSA-5hgm-qm5m-5vmw
Jakarta Tomcat cross-site scripting (XSS) vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-6v52-mj5r-7j2m Apache Tomcat Race Condition vulnerability | CVSS3: 5.9 | 12% Средний | почти 8 лет назад | |
GHSA-6qr6-x7jm-x2q6 Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat | CVSS3: 4.3 | 13% Средний | около 4 лет назад | |
GHSA-6m48-jxwx-76q7 Improper Authentication in Apache Tomcat | 7% Низкий | около 4 лет назад | ||
GHSA-6j8f-66vh-39mj Apache Tomcat Mishandles Character Sequence in Cookies | 17% Средний | около 4 лет назад | ||
GHSA-6j88-6whg-x687 Cross-site Scripting in Apache Tomcat | CVSS3: 6.1 | 6% Низкий | около 4 лет назад | |
GHSA-6gjj-c5mj-4cvp Improper Input Validation in Apache Tomcat | 10% Низкий | около 4 лет назад | ||
GHSA-6cr4-7c7p-p3xv Use of Hard-coded Cryptographic Key in Apache Tomcat | 7% Низкий | около 4 лет назад | ||
GHSA-69r9-qgr7-g2wj Apache Tomcat Missing Encryption of Sensitive Data vulnerability | CVSS3: 7.5 | 43% Средний | 4 месяца назад | |
GHSA-69cc-cv78-qc8g Apache Tomcat: Configured cipher preference order not preserved | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-698c-2x4j-g9gq Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat | CVSS3: 7.5 | 7% Низкий | около 4 лет назад | |
GHSA-68g5-8q7f-m384 Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat | CVSS3: 7.5 | 10% Средний | около 4 лет назад | |
GHSA-653p-vg55-5652 Apache Tomcat Uncontrolled Resource Consumption vulnerability | CVSS3: 5.3 | 2% Низкий | больше 1 года назад | |
GHSA-5xvw-jhvw-hvp2 The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and on Ubuntu 12.04 LTS, 16.04 LTS, and 16.10; and the tomcat8 package before 8.0.14-1+deb8u5 on Debian jessie, before 8.0.32-1ubuntu1.3 on Ubuntu 16.04 LTS, before 8.0.37-1ubuntu0.1 on Ubuntu 16.10, and before 8.0.38-2ubuntu1 on Ubuntu 17.04 might allow local users with access to the tomcat account to gain root privileges via a setgid program in the Catalina directory, as demonstrated by /etc/tomcat8/Catalina/attack. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-5x5f-9r6q-q7mh Apache Tomcat Sensitive Information Disclosure | 5% Низкий | около 4 лет назад | ||
GHSA-5v3h-fjv2-54fg Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue. | CVSS3: 6.5 | 2% Низкий | около 1 месяца назад | |
GHSA-5mp6-jrq3-r938 Apache Tomcat: LockOutRealm treats user names as case-sensitive | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-5m62-pw8w-7w9f Apache Tomcat - Security constraints not correctly applied | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
GHSA-5jpg-mjvg-hfhp Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve. | 5% Низкий | около 4 лет назад | ||
GHSA-5j33-cvvr-w245 Apache Tomcat Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability | CVSS3: 9.8 | 44% Средний | больше 1 года назад | |
GHSA-5hgm-qm5m-5vmw Jakarta Tomcat cross-site scripting (XSS) vulnerability | 9% Низкий | больше 4 лет назад |
Уязвимостей на страницу