Information Exposure Affecting org.apache.tomcat:catalina-ant Open this link in a new tab package, versions [6,6.0.39)
Attack Complexity
Low
User Interaction
Required
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-JAVA-ORGAPACHETOMCAT-30856
-
published
8 Jun 2014
-
disclosed
26 Feb 2014
-
credit
Unknown
Introduced: 26 Feb 2014
CVE-2013-4590 Open this link in a new tabOverview
org.apache.tomcat:catalina-ant
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.