CVE-2018-1305 – org.apache.tomcat.embed:tomcat-embed-core
Package
Manager: maven
Name: org.apache.tomcat.embed:tomcat-embed-core
Vulnerable Version: >=9.0.0m1 <9.0.5 || >=8.5.0 <8.5.28 || >=7.0.0 <7.0.85
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.17655 pctl0.9485
Details
Apache Tomcat information exposure vulnerability Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Metadata
Created: 2018-10-17T16:31:48Z
Modified: 2024-02-23T17:54:01Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-jx6h-3fjx-cgv5/GHSA-jx6h-3fjx-cgv5.json
CWE IDs: []
Alternative ID: GHSA-jx6h-3fjx-cgv5
Finding: F039
Auto approve: 1