logo

CVE-2018-11784 org.apache.tomcat.embed:tomcat-embed-core

Package

Manager: maven
Name: org.apache.tomcat.embed:tomcat-embed-core
Vulnerable Version: >=8.5.0 <8.5.34 || >=7.0.23 <7.0.91 || >=9.0.0 <9.0.12

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.84899 pctl0.99299

Details

Apache Tomcat Open Redirect vulnerability When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

Metadata

Created: 2018-10-17T16:31:02Z
Modified: 2024-02-22T22:43:50Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-5q99-f34m-67gc/GHSA-5q99-f34m-67gc.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-5q99-f34m-67gc
Finding: F156
Auto approve: 1