CVE-2011-2729

Source
https://cve.org/CVERecord?id=CVE-2011-2729
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-2729.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-2729
Downstream
Related
Published
2011-08-15T21:55:02Z
Modified
2026-04-10T03:41:53.351516Z
Summary
[none]
Details

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

References

Affected packages