Skip to content

CVE: 2021-25329 found in tomcat-embed-core - Version: 9.0.36 [JAVA] #156

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageJAVA
VulnerabilityRemote Code Execution
Vulnerability descriptiontomcat-catalina is vulnerable to remote code execution. If a remote attacker knows and is able to control the contents and name of a file, remote code execution can be achieved if the server is configured to use PersistenceManager with a FileStore and the PersistenceManager is configured with the default sessionAttributeValueClassNameFilter="null", through a request that results in the deserialization of the malicious file under the attacker's control. This CVE is due to an incomplete fix for CVE-2020-9484.
CVE2021-25329
CVSS score4.4
Vulnerability present in version/s9.0.0.M1-9.0.41
Found library version/s9.0.36
Vulnerability fixed in version9.0.43
Library latest version11.0.9
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions