QID 996880
Date Published: 2024-01-25
QID 996880: Java (Maven) Security Update for org.apache.tomcat:tomcat (GHSA-w7cg-5969-678w)
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w7cg-5969-678w for updates and patch information.
Vendor References
- GHSA-w7cg-5969-678w -
github.com/advisories/GHSA-w7cg-5969-678w
CVEs related to QID 996880
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w7cg-5969-678w | org.apache.tomcat:tomcat |
|