Lucene search

K
githubGitHub Advisory DatabaseGHSA-58HJ-575G-5J25
HistoryApr 30, 2022 - 6:16 p.m.

Apache Tomcat allows webmasters to insert xss into error messages

2022-04-3018:16:47
CWE-80
GitHub Advisory Database
github.com
6
apache tomcat
xss
vulnerability
error messages

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

38.1%

A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

Affected configurations

Vulners
Node
org.apache.tomcat\Matchtomcat

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

EPSS

0.001

Percentile

38.1%