Access restriction bypass in Apache Tomcat
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 21, 2024
Package
Affected versions
>= 7.0.12, < 7.0.14
Patched versions
7.0.14
Description
Published by the National Vulnerability Database
May 20, 2011
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 14, 2023
Last updated
Feb 21, 2024
Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
References