GHSA-w97x-xfxf-f9xj

Suggest an improvement
Source
https://github.com/advisories/GHSA-w97x-xfxf-f9xj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-w97x-xfxf-f9xj/GHSA-w97x-xfxf-f9xj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w97x-xfxf-f9xj
Aliases
  • CVE-2003-0045
Published
2022-04-29T01:25:43Z
Modified
2023-11-08T03:56:45.164061Z
Summary
Jakarta Tomcat Denial of Service vulnerability
Details

Jakarta Tomcat before 3.3.1a on certain Windows systems may allow remote attackers to cause a denial of service (thread hang and resource consumption) via a request for a JSP page containing an MS-DOS device name, such as aux.jsp.

Database specific
{
    "nvd_published_at": "2003-02-07T05:00:00Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2023-09-18T22:43:28Z"
}
References

Affected packages

Maven / org.apache.tomcat:tomcat

Package

Name
org.apache.tomcat:tomcat
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.3.1a