Uncontrolled external site redirect In org.apache.tomcat.embed:tomcat-embed-core
Description
Apache Tomcat Open Redirect vulnerability When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | >=7.0.23 <=7.0.90 || >=8.5.0 <=8.5.33 || >=9.0.0 <=9.0.11 | 7.0.91, 8.5.34, 9.0.12 | |
maven | >=8.5.0 <8.5.34 || >=7.0.23 <7.0.91 || >=9.0.0 <9.0.12 | 8.5.34, 7.0.91, 9.0.12 | |
rpm rhel7 | <0:7.0.76-9.el7_6 | 0:7.0.76-9.el7_6 |
Aliases
References
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.