Lucene search

K
osvGoogleOSV:GHSA-RH8Q-VJGF-GF74
HistoryMay 14, 2022 - 1:10 a.m.

Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat

2022-05-1401:10:16
Google
osv.dev
20
apache tomcat
mapper component
security constraints
remote attackers
directory
url

EPSS

0.005

Percentile

77.1%

The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.

References