Overview
About vulnerability
Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected
Description: When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied.
Mitigation: Users of the affected versions should apply one of the following mitigations:
- Upgrade to Apache Tomcat 11.0.22 or later
- Upgrade to Apache Tomcat 10.1.55 or later
- Upgrade to Apache Tomcat 9.0.118 or later
Details
- Affected product:
- AlmaLinux 9.2 ESU , Amazon Linux 2 ELS , Apache CXF , Apache Log4j , Apache Tapestry , Apache Tomcat , CentOS 7 ELS , Debian 10 ELS , Spring , TuxCare 9.6 ESU , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS , camel , grails-core , logging-flume , thrift
- Affected packages:
- tomcat7 @ 7.0.68 (+5183 more)