Lucene search

K
osvGoogleOSV:GHSA-QPRX-Q2R7-3RX6
HistoryMay 14, 2022 - 1:10 a.m.

Improper Input Validation in Apache Tomcat

2022-05-1401:10:18
Google
osv.dev
64
apache tomcat
input validation
remote attackers
arbitrary files
security issue
xml external entity (xxe)

EPSS

0.001

Percentile

47.5%

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References