Reflected cross-site scripting (XSS) In org.apache.tomcat.embed:tomcat-embed-core
Description
Cross-site scripting in Apache Tomcat The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 9.0.16-4 | ||
maven | 7.0.94, 8.5.40, 9.0.19 | ||
debian 12 | 9.0.16-4 | ||
maven | 9.0.17, 8.5.40, 7.0.94 | ||
debian 13 | 9.0.16-4 | ||
maven | 9.0.17, 8.5.40, 7.0.94 | ||
debian 14 | 9.0.16-4 | ||
rpm rhel6 | - | - | |
rpm rhel8 | - | - | |
rpm rhel7 | - | - |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39. 40. 41.