Skip to content

CVE: 2021-30640 found in tomcat-embed-core - Version: 9.0.36 [JAVA] #157

Description

@Rajkumarr77

Veracode Software Composition Analysis

AttributeDetails
Librarytomcat-embed-core
DescriptionCore Tomcat implementation
LanguageJAVA
VulnerabilityAccess Restriction Bypass
Vulnerability descriptiontomcat-catalina is vulnerable to access restriction bypass. Lack of proper sanitization of user provided parameter or configuration data provided by an administrator accept authentication using variations of their user name and/or to bypass some of the protection provided by the LockOut Realm.
CVE2021-30640
CVSS score5.8
Vulnerability present in version/s9.0.0.M1-9.0.45
Found library version/s9.0.36
Vulnerability fixed in version9.0.46
Library latest version11.0.9
Fix

Links:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions