QID 982007

QID 982007: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-5q99-f34m-67gc)

When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-5q99-f34m-67gc for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982007

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5q99-f34m-67gc org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-5q99-f34m-67gc