Lack of data validation In org.apache.tomcat:tomcat-util
Description
Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Tomcat Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 6.0.40, 7.0.54, 8.0.6 | ||
maven | 6.0.40, 7.0.54, 8.0.6 | ||
rpm rhel5 | - | - | |
rpm rhel7 | 0:7.0.42-6.el7_0 | ||
rpm rhel6 | 0:6.0.24-72.el6_5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25. 26. 27. 28. 29. 30. 31. 32. 33. 34. 35. 36. 37. 38. 39. 40. 41. 42. 43. 44. 45. 46. 47. 48. 49. 50.