Lucene search

K
osvGoogleOSV:GHSA-4PRH-GQW8-RGH5
HistoryMay 01, 2022 - 5:44 p.m.

Apache Tomcat Directory Traversal

2022-05-0117:44:16
Google
osv.dev
17
tomcat 5.x
tomcat 6.x
proxy modules
mod_proxy
mod_rewrite
mod_jk
remote attackers
arbitrary files
directory traversal
url-encoded backslash
apache

EPSS

0.974

Percentile

99.9%

Directory traversal vulnerability in Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) / (slash), (2) \ (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

References