Lucene search

K
osvGoogleOSV:GHSA-HJFH-7C4V-7Q8H
HistoryMay 02, 2022 - 3:39 a.m.

Improper Authentication in Apache Tomcat

2022-05-0203:39:47
Google
osv.dev
11

0.002 Low

EPSS

Percentile

57.8%

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

References