VDB
KO
MEDIUM 6.1

GHSA-jjpq-gp5q-8q6w

Cross-site scripting in Apache Tomcat

Details

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in: 9.0.0 Fixed in: 9.0.17
Fix # pom.xml: bump <version>9.0.17</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in: 8.5.0 Fixed in: 8.5.40
Fix # pom.xml: bump <version>8.5.40</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in: 7.0.0 Fixed in: 7.0.94
Fix # pom.xml: bump <version>7.0.94</version> for org.apache.tomcat.embed:tomcat-embed-core
Maven / org.apache.tomcat:tomcat-catalina
Introduced in: 9.0.0 Fixed in: 9.0.17
Fix # pom.xml: bump <version>9.0.17</version> for org.apache.tomcat:tomcat-catalina
Maven / org.apache.tomcat:tomcat-catalina
Introduced in: 8.5.0 Fixed in: 8.5.40
Fix # pom.xml: bump <version>8.5.40</version> for org.apache.tomcat:tomcat-catalina
Maven / org.apache.tomcat:tomcat-catalina
Introduced in: 7.0.0 Fixed in: 7.0.94
Fix # pom.xml: bump <version>7.0.94</version> for org.apache.tomcat:tomcat-catalina
Maven / org.apache.tomcat:tomcat
Introduced in: 9.0.0 Fixed in: 9.0.17
Fix # pom.xml: bump <version>9.0.17</version> for org.apache.tomcat:tomcat
Maven / org.apache.tomcat:tomcat
Introduced in: 8.5.0 Fixed in: 8.5.40
Fix # pom.xml: bump <version>8.5.40</version> for org.apache.tomcat:tomcat
Maven / org.apache.tomcat:tomcat
Introduced in: 7.0.0 Fixed in: 7.0.94
Fix # pom.xml: bump <version>7.0.94</version> for org.apache.tomcat:tomcat

References