org.apache.tomcat.embed:tomcat-embed-core@9.0.46 vulnerabilities
-
latest version
11.0.0
-
latest non vulnerable version
-
first published
14 years ago
-
latest version published
2 months ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.apache.tomcat.embed:tomcat-embed-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Uncaught Exception due to the custom Jakarta Authentication Note: This is only exploitable if Tomcat is configured to use a custom Jakarta Authentication
How to fix Uncaught Exception? Upgrade |
[9.0.0.M1,9.0.96)
[10.1.0-M1,10.1.31)
[11.0.0-M1,11.0.0)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the How to fix Allocation of Resources Without Limits or Throttling? Upgrade |
[9.0.13,9.0.90)
[10.1.0-M1,10.1.25)
[11.0.0-M1,11.0.0-M21)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Insufficient Session Expiration due to an infinite timeout being assigned to an open connection improperly, in How to fix Insufficient Session Expiration? Upgrade |
[,9.0.90)
[10.1.0-M1,10.1.25)
[11.0.0-M1,11.0.0-M21)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Denial of Service (DoS) when processing a crafted HTTP/2 request. If the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed. How to fix Denial of Service (DoS)? Upgrade |
[8.5.0,8.5.99)
[9.0.0-M1,9.0.86)
[10.1.0-M1,10.1.19)
[11.0.0-M1,1.0.0-M17)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Improper Input Validation due to the improper parsing of HTTP trailer headers. An attacker can manipulate the server into treating a single request as multiple requests by sending a trailer header that exceeds the header size limit. This could lead to request smuggling when the server is behind a reverse proxy. How to fix Improper Input Validation? Upgrade |
[8.5.0,8.5.96)
[9.0.0-M1,9.0.83)
[10.1.0-M1,10.1.16)
[11.0.0-M1,11.0.0-M10)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Incomplete Cleanup when recycling various internal objects. An error could cause some parts of the recycling process to be skipped, leading to information leaking from the current request/response to the next. An attacker can gain unauthorised access to sensitive information by exploiting this error. How to fix Incomplete Cleanup? Upgrade |
[8.5.0,8.5.94)
[9.0.0-M1,9.0.81)
[10.1.0-M1,10.1.14)
[11.0.0-M1,11.0.0-M12)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Improper Input Validation due to the improper handling of How to fix Improper Input Validation? Upgrade |
[8.5.0,8.5.94)
[9.0.0-M1,9.0.81)
[10.1.0-M1,10.1.14)
[11.0.0-M1,11.0.0-M12)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Denial of Service (DoS) in the implementation of the HTTP/2 protocol. An attacker can cause a denial of service (including via DDoS) by rapidly resetting many streams through request cancellation. How to fix Denial of Service (DoS)? Upgrade |
[,8.5.94)
[9.0.0,9.0.81)
[10.0.0,10.1.14)
[11.0.0-M3,11.0.0-M12)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Access Restriction Bypass. If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice. The vulnerability is limited to the ROOT (default) web application. How to fix Access Restriction Bypass? Upgrade |
[8.5.0,8.5.93)
[9.0.0-M1,9.0.80)
[10.1.0-M1,10.1.13)
[11.0.0-M1,11.0.0-M11)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Unprotected Transport of Credentials when using the How to fix Unprotected Transport of Credentials? Upgrade |
[8.5.0,8.5.86)
[9.0.0-M1,9.0.72)
[10.1.0-M1,10.1.6)
[11.0.0-M1,11.0.0-M3)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Denial of Service (DoS) when an attacker sends a large number of request parts in a series of uploads or a single multipart upload. NOTE: After upgrading to the fixed version, the How to fix Denial of Service (DoS)? Upgrade |
[8.5.0,8.5.85)
[9.0.0-M1,9.0.71)
[10.1.0-M1,10.1.5)
[11.0.0-M1,11.0.0-M3)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Improper Input Validation such that the How to fix Improper Input Validation? Upgrade |
[8.5.83,8.5.84)
[9.0.40,9.0.69)
[10.1.0-M1,10.1.2)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to HTTP Request Smuggling when improper requests containing an invalid Note: Exploiting this vulnerability is also possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. How to fix HTTP Request Smuggling? Upgrade |
[8.5.0,8.5.53)
[9.0.0-M1,9.0.68)
[10.0.0-M1,10.0.27)
[10.1.0-M1,10.1.1)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Information Exposure.
due to a concurrency bug that could cause client connections to share an How to fix Information Exposure? Upgrade |
[8.5.0,8.5.78)
[9.0.0-M1,9.0.62)
[10.0.0-M1,10.0.20)
[10.1.0-M1,10.1.0-M14)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to Privilege Escalation via a How to fix Privilege Escalation? Upgrade |
[8.5.55,8.5.75)
[9.0.0,9.0.58)
[10.0.0-M1,10.0.16)
[10.1.0-M1,10.1.0-M10)
|
org.apache.tomcat.embed:tomcat-embed-core is a Core Tomcat implementation. Affected versions of this package are vulnerable to HTTP Request Smuggling. Tomcat does not correctly parse the HTTP transfer-encoding request header in some circumstances, leading to the possibility of request smuggling when used with a reverse proxy. Specifically, Tomcat incorrectly ignores the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; it honours the identify encoding; and it does not ensure that, if present, the chunked encoding was the final encoding. How to fix HTTP Request Smuggling? Upgrade |
[10.0.0-M1,10.0.7)
[9.0.0.M1,9.0.48)
[8.5.0,8.5.68)
|