Количество 1 533
Количество 1 533
GHSA-wf5v-jhxj-q632
Denial of service in Apache Tomcat
GHSA-wc4r-xq3c-5cf3
Apache Tomcat - Security constraint bypass for pre/post-resources
GHSA-w97x-xfxf-f9xj
Jakarta Tomcat Denial of Service vulnerability
GHSA-w7cg-5969-678w
Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token
GHSA-w6q7-ww2x-7gm3
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
GHSA-w65j-cmqc-37p2
JULI logging component in Apache Tomcat does not restrict certain permissions for web applications
GHSA-w3xg-786f-g788
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
GHSA-w3j5-q8f2-3cqq
Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat
GHSA-w227-xcfx-3pj8
Exposure of Sensitive Information in Apache Tomcat
GHSA-vfww-5hm6-hx2j
Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences
GHSA-vch7-92vf-jm44
Apache Tomcat does not follow ServletSecurity annotations
GHSA-v682-8vv8-vpwr
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
GHSA-v66v-63h2-8q5q
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
GHSA-v5p2-vg3c-pmrr
Apache Tomcat Path Traversal Vulnerability
GHSA-v35g-wxj7-gxp3
Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.
GHSA-rv64-5gf8-9qq8
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
GHSA-rq2w-37h9-vg94
Apache Tomcat improperly escapes input from JsonErrorReportValve
GHSA-rpf9-hrjr-88fv
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
GHSA-rp8h-vr48-4j8p
Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests
GHSA-rh8q-vjgf-gf74
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-wf5v-jhxj-q632 Denial of service in Apache Tomcat | 8% Низкий | больше 4 лет назад | ||
GHSA-wc4r-xq3c-5cf3 Apache Tomcat - Security constraint bypass for pre/post-resources | 4% Низкий | около 1 года назад | ||
GHSA-w97x-xfxf-f9xj Jakarta Tomcat Denial of Service vulnerability | 2% Низкий | больше 4 лет назад | ||
GHSA-w7cg-5969-678w Apache Tomcat allows remote attackers to bypass a CSRF protection mechanism by using a token | CVSS3: 8.8 | 10% Низкий | больше 4 лет назад | |
GHSA-w6q7-ww2x-7gm3 Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat | 53% Средний | больше 4 лет назад | ||
GHSA-w65j-cmqc-37p2 JULI logging component in Apache Tomcat does not restrict certain permissions for web applications | 5% Низкий | больше 4 лет назад | ||
GHSA-w3xg-786f-g788 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.46 through 8.5.100, from 7.0.97 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue. | CVSS3: 8.1 | 1% Низкий | 19 дней назад | |
GHSA-w3j5-q8f2-3cqq Concurrent Execution using Shared Resource with Improper Synchronization in Apache Tomcat | CVSS3: 7.5 | 16% Средний | больше 4 лет назад | |
GHSA-w227-xcfx-3pj8 Exposure of Sensitive Information in Apache Tomcat | 94% Критический | больше 4 лет назад | ||
GHSA-vfww-5hm6-hx2j Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences | CVSS3: 9.6 | 10% Средний | 11 месяцев назад | |
GHSA-vch7-92vf-jm44 Apache Tomcat does not follow ServletSecurity annotations | 7% Низкий | больше 4 лет назад | ||
GHSA-v682-8vv8-vpwr Denial of Service via incomplete cleanup vulnerability in Apache Tomcat | CVSS3: 6.3 | 2% Низкий | больше 2 лет назад | |
GHSA-v66v-63h2-8q5q Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action. | 59% Средний | больше 4 лет назад | ||
GHSA-v5p2-vg3c-pmrr Apache Tomcat Path Traversal Vulnerability | 40% Средний | больше 4 лет назад | ||
GHSA-v35g-wxj7-gxp3 Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | 10% Низкий | больше 4 лет назад | ||
GHSA-rv64-5gf8-9qq8 Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-rq2w-37h9-vg94 Apache Tomcat improperly escapes input from JsonErrorReportValve | CVSS3: 7.5 | 3% Низкий | больше 3 лет назад | |
GHSA-rpf9-hrjr-88fv Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
GHSA-rp8h-vr48-4j8p Apache Tomcat Exposes IP Addresses and HTTP Headers of Requests | 6% Низкий | больше 4 лет назад | ||
GHSA-rh8q-vjgf-gf74 Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat | CVSS3: 5.3 | 18% Средний | больше 4 лет назад |
Уязвимостей на страницу