CVE-2020-17521
- EPSS 1.05%
- Veröffentlicht 07.12.2020 20:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operatin...
CVE-2020-11979
- EPSS 8.24%
- Veröffentlicht 01.10.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 04:59:02
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without ...
CVE-2020-13935
- EPSS 86.61%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...
CVE-2020-13934
- EPSS 64.12%
- Veröffentlicht 14.07.2020 15:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...
- EPSS 56.64%
- Veröffentlicht 20.05.2020 19:15:09
- Zuletzt bearbeitet 25.08.2026 16:28:27
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the Persiste...
CVE-2020-1945
- EPSS 1.81%
- Veröffentlicht 14.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:42
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files fr...
CVE-2020-1938
- EPSS 99.27%
- Veröffentlicht 24.02.2020 22:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available t...
CVE-2020-1935
- EPSS 9.39%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:38
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smug...
CVE-2019-17569
- EPSS 8.87%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of H...
CVE-2019-17563
- EPSS 10.69%
- Veröffentlicht 23.12.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:32
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be p...