Lucene search

K
osvGoogleOSV:GHSA-68G5-8Q7F-M384
HistoryMay 14, 2022 - 12:58 a.m.

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

2022-05-1400:58:29
Google
osv.dev
13

0.002 Low

EPSS

Percentile

55.1%

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

References