Directory traversal vulnerability in source.jsp of Apache Tomcat before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the argument to source.jsp.
{
    "nvd_published_at": "2002-03-22T05:00:00Z",
    "github_reviewed_at": "2023-09-18T21:59:42Z",
    "cwe_ids": [
        "CWE-22"
    ],
    "severity": "MODERATE",
    "github_reviewed": true
}