QID 980338

QID 980338: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-jgwr-3qm3-26f3)

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Customers are advised to refer to GHSA-jgwr-3qm3-26f3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980338

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jgwr-3qm3-26f3 org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-jgwr-3qm3-26f3