logo

Database

Lack of data validation - Path Traversal In org.apache.tomcat:tomcat

Description

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/tomcat80/commit/c15c2aba8eb42425f9ebcfcaef579dada38ad3a22. https://github.com/apache/tomcat/commit/127d8ea86d245846f0472865f0eb1eb111955e713. https://github.com/apache/tomcat/commit/58c09b6217c546e1a251a82da227018f052772284. https://github.com/apache/tomcat/commit/66daa4adc14b3e939659879153c0a579fdfcb0995. https://github.com/apache/tomcat/commit/7288bc70a14edcfeff0a96e333a858be374cfc646. https://github.com/apache/tomcat/commit/816552abf6735fa37dfd37c8a7bfbdbd045477e07. https://github.com/apache/tomcat/commit/8437193708e4bf6b2861a7953dc472f9dad491118. https://github.com/apache/tomcat/commit/89cd0cf33a99dbbcf5c69050a83b6876e39269d79. https://github.com/apache/tomcat/commit/a273b5f45cb46a273d06510a689fc314155a952d10. https://github.com/apache/tomcat/commit/c584c7c4ab0686e4125eefcd0afb32fb8269da3d11. https://github.com/apache/tomcat80/commit/2b643a4e36d318d55ec57fee57610671656d23c012. https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b@%3Cdev.tomcat.apache.org%3E13. https://lists.apache.org/thread.html/r587e50b86c1a96ee301f751d50294072d142fd6dc08a8987ae9f3a9b%40%3Cdev.tomcat.apache.org%3E14. https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c@%3Cdev.tomcat.apache.org%3E15. https://lists.apache.org/thread.html/r03c597a64de790ba42c167efacfa23300c3d6c9fe589ab87fe02859c%40%3Cdev.tomcat.apache.org%3E16. https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb@%3Cdev.tomcat.apache.org%3E17. https://lists.apache.org/thread.html/b8a1bf18155b552dcf9a928ba808cbadad84c236d85eab3033662cfb%40%3Cdev.tomcat.apache.org%3E18. https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95@%3Cdev.tomcat.apache.org%3E19. https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3E20. https://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c@%3Cdev.tomcat.apache.org%3E21. https://security.netapp.com/advisory/ntap-20180531-000122. https://web.archive.org/web/20160321235514/http://www.securitytracker.com/id/103507123. https://web.archive.org/web/20160804024910/http://www.securityfocus.com/bid/8332824. https://lists.apache.org/thread.html/b84ad1258a89de5c9c853c7f2d3ad77e5b8b2930be9e132d5cef6b95%40%3Cdev.tomcat.apache.org%3E25. https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b@%3Cdev.tomcat.apache.org%3E26. https://lists.apache.org/thread.html/39ae1f0bd5867c15755a6f959b271ade1aea04ccdc3b2e639dcd903b%40%3Cdev.tomcat.apache.org%3E27. https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113@%3Cdev.tomcat.apache.org%3E28. https://lists.apache.org/thread.html/37220405a377c0182d2afdbc36461c4783b2930fbeae3a17f1333113%40%3Cdev.tomcat.apache.org%3E29. https://kc.mcafee.com/corporate/index?page=content&id=SB1015630. https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c0515862631. https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c0515044232. https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c0505496433. https://bz.apache.org/bugzilla/show_bug.cgi?id=5876534. https://bto.bluecoat.com/security-advisory/sa11835. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00047.html36. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00069.html37. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00082.html38. http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00085.html39. http://marc.info/?l=bugtraq&m=145974991225029&w=240. http://packetstormsecurity.com/files/135892/Apache-Tomcat-Directory-Disclosure.html41. http://rhn.redhat.com/errata/RHSA-2016-1089.html42. http://rhn.redhat.com/errata/RHSA-2016-2045.html43. http://rhn.redhat.com/errata/RHSA-2016-2599.html44. http://seclists.org/bugtraq/2016/Feb/14645. http://seclists.org/fulldisclosure/2016/Feb/12246. http://svn.apache.org/viewvc?view=revision&revision=171520647. http://svn.apache.org/viewvc?view=revision&revision=171520748. http://svn.apache.org/viewvc?view=revision&revision=171521349. http://svn.apache.org/viewvc?view=revision&revision=171521650. http://svn.apache.org/viewvc?view=revision&revision=171688251. http://svn.apache.org/viewvc?view=revision&revision=171689452. http://svn.apache.org/viewvc?view=revision&revision=171720953. http://svn.apache.org/viewvc?view=revision&revision=171721254. http://svn.apache.org/viewvc?view=revision&revision=171721655. http://tomcat.apache.org/security-6.html56. http://tomcat.apache.org/security-7.html57. http://tomcat.apache.org/security-8.html58. http://tomcat.apache.org/security-9.html59. http://www.debian.org/security/2016/dsa-353060. http://www.debian.org/security/2016/dsa-355261. http://www.debian.org/security/2016/dsa-360962. http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html63. http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html64. http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html65. http://www.qcsec.com/blog/CVE-2015-5345-apache-tomcat-vulnerability.html66. http://www.ubuntu.com/usn/USN-3024-1