GHSA-r6cf-cr44-m8rr

Suggest an improvement
Source
https://github.com/advisories/GHSA-r6cf-cr44-m8rr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-r6cf-cr44-m8rr/GHSA-r6cf-cr44-m8rr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r6cf-cr44-m8rr
Aliases
  • CVE-2002-2009
Published
2022-04-30T18:22:19Z
Modified
2025-04-03T16:57:13.676439Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache Tomcat Leaks Pathname Information via Error Message
Details

Apache Tomcat 4.0.1 allows remote attackers to obtain the web root path via HTTP requests for JSP files preceded by (1) +/, (2) >/, (3)

Database specific
{
    "github_reviewed": true,
    "nvd_published_at": "2002-12-31T05:00:00Z",
    "cwe_ids": [
        "CWE-209"
    ],
    "github_reviewed_at": "2025-04-03T16:15:45Z",
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Last affected
4.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-r6cf-cr44-m8rr/GHSA-r6cf-cr44-m8rr.json"