Skip to content

CVE: 2021-24122 found in tomcat-embed-core - Version: 9.0.36 [JAVA] #154

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageJAVA
VulnerabilityInformation Disclosure
Vulnerability descriptionapache tomcat is vulnerable to information disclosure. Security constraints can be bypassed to obtain and view JSP source code in certain configurations, when serving resources from a network location using the NTFS file system. The vulnerability is caused by the insufficient validation for the : character in the file path.
CVE2021-24122
CVSS score4.3
Vulnerability present in version/s9.0.0.M1-9.0.39
Found library version/s9.0.36
Vulnerability fixed in version9.0.40
Library latest version11.0.9
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions