BIT-tomcat-2021-24122

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2021-24122.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2021-24122
Aliases
Published
2024-03-06T11:10:27.482Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.

Database specific
{
    "cpes": [
        "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:10.0.0:milestone9:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*",
        "cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.0.106
Introduced
8.5.0
Fixed
8.5.59
Introduced
9.0.1
Fixed
9.0.39
Type
SEMVER
Events
Introduced
9.0.0-milestone1
Last affected
9.0.0-milestone1
Introduced
9.0.0-milestone10
Last affected
9.0.0-milestone10
Introduced
9.0.0-milestone11
Last affected
9.0.0-milestone11
Introduced
9.0.0-milestone12
Last affected
9.0.0-milestone12
Introduced
9.0.0-milestone13
Last affected
9.0.0-milestone13
Introduced
9.0.0-milestone14
Last affected
9.0.0-milestone14
Introduced
9.0.0-milestone15
Last affected
9.0.0-milestone15
Introduced
9.0.0-milestone16
Last affected
9.0.0-milestone16
Introduced
9.0.0-milestone17
Last affected
9.0.0-milestone17
Introduced
9.0.0-milestone18
Last affected
9.0.0-milestone18
Introduced
9.0.0-milestone19
Last affected
9.0.0-milestone19
Introduced
9.0.0-milestone2
Last affected
9.0.0-milestone2
Introduced
9.0.0-milestone20
Last affected
9.0.0-milestone20
Introduced
9.0.0-milestone21
Last affected
9.0.0-milestone21
Introduced
9.0.0-milestone22
Last affected
9.0.0-milestone22
Introduced
9.0.0-milestone23
Last affected
9.0.0-milestone23
Introduced
9.0.0-milestone24
Last affected
9.0.0-milestone24
Introduced
9.0.0-milestone25
Last affected
9.0.0-milestone25
Introduced
9.0.0-milestone26
Last affected
9.0.0-milestone26
Introduced
9.0.0-milestone27
Last affected
9.0.0-milestone27
Introduced
9.0.0-milestone3
Last affected
9.0.0-milestone3
Introduced
9.0.0-milestone4
Last affected
9.0.0-milestone4
Introduced
9.0.0-milestone5
Last affected
9.0.0-milestone5
Introduced
9.0.0-milestone6
Last affected
9.0.0-milestone6
Introduced
9.0.0-milestone7
Last affected
9.0.0-milestone7
Introduced
9.0.0-milestone8
Last affected
9.0.0-milestone8
Introduced
9.0.0-milestone9
Last affected
9.0.0-milestone9
Introduced
10.0.0-milestone1
Last affected
10.0.0-milestone1
Introduced
10.0.0-milestone2
Last affected
10.0.0-milestone2
Introduced
10.0.0-milestone3
Last affected
10.0.0-milestone3
Introduced
10.0.0-milestone4
Last affected
10.0.0-milestone4
Introduced
10.0.0-milestone5
Last affected
10.0.0-milestone5
Introduced
10.0.0-milestone6
Last affected
10.0.0-milestone6
Introduced
10.0.0-milestone7
Last affected
10.0.0-milestone7
Introduced
10.0.0-milestone8
Last affected
10.0.0-milestone8
Introduced
10.0.0-milestone9
Last affected
10.0.0-milestone9