QID 995378
Date Published: 2023-09-25
QID 995378: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-xmc9-6p56-3c4v)
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xmc9-6p56-3c4v for updates and patch information.
Vendor References
- GHSA-xmc9-6p56-3c4v -
github.com/advisories/GHSA-xmc9-6p56-3c4v
CVEs related to QID 995378
Software Advisories
| Advisory ID | Software | Component | Link |
|---|