QID 982093

QID 982093: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-344f-f5vg-2jfj)

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Customers are advised to refer to GHSA-344f-f5vg-2jfj for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982093

    Software Advisories
    Advisory ID Software Component Link
    GHSA-344f-f5vg-2jfj org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-344f-f5vg-2jfj