VDB
EN
HIGH 7.0

GHSA-jgwr-3qm3-26f3

Potential remote code execution in Apache Tomcat

빠른 조치

GHSA-jgwr-3qm3-26f3 — org.apache.tomcat.embed:tomcat-embed-core: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>10.0.2</version> for org.apache.tomcat.embed:tomcat-embed-core

상세

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 10.0.0-M1 수정 버전: 10.0.2
수정 # pom.xml: bump <version>10.0.2</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 9.0.0 수정 버전: 9.0.41
수정 # pom.xml: bump <version>9.0.41</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 8.0.0 수정 버전: 8.5.61
수정 # pom.xml: bump <version>8.5.61</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
최초 영향 버전: 7.0.0 수정 버전: 7.0.108
수정 # pom.xml: bump <version>7.0.108</version> for org.apache.tomcat.embed:tomcat-embed-core

참고