Lucene search

K
osvGoogleOSV:CVE-2017-7675
HistoryAug 11, 2017 - 2:29 a.m.

CVE-2017-7675

2017-08-1102:29:00
Google
osv.dev
7

6.7 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.1%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

References

6.7 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

55.1%