QID 995381
Date Published: 2023-09-25
QID 995381: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-4prh-gqw8-rgh5)
Directory traversal vulnerability in Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) / (slash), (2) \ (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4prh-gqw8-rgh5 for updates and patch information.
Vendor References
- GHSA-4prh-gqw8-rgh5 -
github.com/advisories/GHSA-4prh-gqw8-rgh5
CVEs related to QID 995381
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4prh-gqw8-rgh5 | org.apache.tomcat:tomcat |
|