Lucene search

K
githubGitHub Advisory DatabaseGHSA-3P5R-7CW3-2M67
HistoryMay 17, 2022 - 2:44 a.m.

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

2022-05-1702:44:28
CWE-200
GitHub Advisory Database
github.com
4

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

58.7%

java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request information intended for other applications in opportunistic circumstances via an application that records the requests that it processes.

Affected configurations

Vulners
Node
org.apache.tomcat\Matchtomcat
CPENameOperatorVersion
org.apache.tomcat:tomcatlt7.0.40

References

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:H/Au:N/C:P/I:N/A:N

0.002 Low

EPSS

Percentile

58.7%