QID 996420
Date Published: 2023-12-26
QID 996420: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-qfw2-wvrw-mvw4)
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qfw2-wvrw-mvw4 for updates and patch information.
Vendor References
- GHSA-qfw2-wvrw-mvw4 -
github.com/advisories/GHSA-qfw2-wvrw-mvw4
CVEs related to QID 996420
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qfw2-wvrw-mvw4 | org.apache.tomcat:tomcat |
|