Description
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5023 | The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information. |
Github GHSA |
GHSA-qrcx-p4rr-g48h | Apache Tomcat allows remote attackers to read JSP source files |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-08T00:01:23.292Z
Reserved: 2007-04-10T00:00:00.000Z
Link: CVE-2005-4836
No data.
Status : Deferred
Published: 2005-12-31T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2005-4836
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA