GHSA-mg4v-rf8p-ghqq

Suggest an improvement
Source
https://github.com/advisories/GHSA-mg4v-rf8p-ghqq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mg4v-rf8p-ghqq/GHSA-mg4v-rf8p-ghqq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mg4v-rf8p-ghqq
Aliases
  • CVE-2011-1088
Published
2022-05-14T02:56:11Z
Modified
2024-02-27T22:41:44.754941Z
Summary
Apache Tomcat allows remote attackers to bypass intended access restrictions
Details

Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.

Database specific
{
    "nvd_published_at": "2011-03-14T19:55:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-27T21:57:25Z"
}
References

Affected packages

Maven / org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.10