org.apache.tomcat:tomcat@10.1.55

  • latest version

    11.0.24

  • latest non vulnerable version

  • first published

    13 years ago

  • latest version published

    1 months ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.apache.tomcat:tomcat package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the number guess process. An attacker can execute arbitrary JavaScript code in the context of a user's browser by injecting malicious scripts into the web page.

    How to fix Cross-site Scripting (XSS)?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
    • M
    Always-Incorrect Control Flow Implementation

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Always-Incorrect Control Flow Implementation due to incorrect control flow in the RewriteValve process. An attacker can bypass intended rewrite rules by crafting requests that exploit the improper evaluation of OR chains in conditions.

    How to fix Always-Incorrect Control Flow Implementation?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
    • M
    Always-Incorrect Control Flow Implementation

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Always-Incorrect Control Flow Implementation due to the incomplete logging of the effective web.xml when special roles and empty authorization constraints are present. An attacker can bypass intended access restrictions by exploiting the absence of these constraints in the logged configuration.

    How to fix Always-Incorrect Control Flow Implementation?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
    • M
    Improper Authorization

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Improper Authorization due to the improper enforcement of security constraints in the default servlet when certain HTTP methods or method omissions are configured. An attacker can gain unauthorized access to protected resources by sending requests using HTTP methods that are not properly restricted.

    How to fix Improper Authorization?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.0.M1,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)
    • H
    Detection of Error Condition Without Action

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Detection of Error Condition Without Action due to improper handling of invalid certificate revocation list (CRL) configurations in the FFM connector. An attacker can bypass intended certificate validation by supplying an invalid CRL configuration.

    How to fix Detection of Error Condition Without Action?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.83,9.0.119)[10.1.0-M7,10.1.56)[11.0.0-M1,11.0.23)
    • H
    Improper Authentication

    org.apache.tomcat:tomcat is an implementation of the Java Servlet, JavaServer Pages, Java Expression Language and Java WebSocket technologies.

    Affected versions of this package are vulnerable to Improper Authentication in the EncryptionInterceptor process of the cluster component. An attacker can gain unauthorized access or perform unauthorized actions by replaying previously captured authentication data.

    How to fix Improper Authentication?

    Upgrade org.apache.tomcat:tomcat to version 9.0.119, 10.1.56, 11.0.23 or higher.

    [9.0.13,9.0.119)[10.1.0-M1,10.1.56)[11.0.0-M1,11.0.23)