漏洞标题
N/A
漏洞描述信息
在Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 和 6.0.16 to 6.0.48 中,NIO HTTP 连接器发送文件代码的错误处理中存在一个错误,导致当前Processor对象多次被添加到Processor缓存中。这反过来意味着同一个Processor对象可以被用于并发请求。共享Processor可能导致请求之间的信息泄露,包括但不限于会话ID和响应体。该错误最初在8.5.x版本中发现,似乎8.5.x版本的Connector代码 refactoring 使得观察到该错误的可能性更大。最初认为8.5.x的 refactoring 引入了该错误,但进一步的研究表明,该错误在所有当前支持的Tomcat版本中都存在。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent requests. Sharing a Processor can result in information leakage between requests including, not not limited to, session ID and the response body. The bug was first noticed in 8.5.x onwards where it appears the refactoring of the Connector code for 8.5.x onwards made it more likely that the bug was observed. Initially it was thought that the 8.5.x refactoring introduced the bug but further investigation has shown that the bug is present in all currently supported Tomcat versions.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Apache Tomcat 信息泄露漏洞
漏洞描述信息
Apache Tomcat是美国阿帕奇(Apache)软件基金会下属的Jakarta项目的一款轻量级Web应用服务器,它主要用于开发和调试JSP程序,适用于中小型系统。 Apache Tomcat 9.0.0.M1至9.0.0.M13版本和8.5.0至8.5.8版本中存在信息泄露漏洞。攻击者可利用该漏洞获取敏感信息。
CVSS信息
N/A
漏洞类别
代码问题