QID 995387
Date Published: 2023-09-25
QID 995387: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-qff8-g48j-pwpw)
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes (') as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qff8-g48j-pwpw for updates and patch information.
Vendor References
- GHSA-qff8-g48j-pwpw -
github.com/advisories/GHSA-qff8-g48j-pwpw
CVEs related to QID 995387
Software Advisories
| Advisory ID | Software | Component | Link |
|---|