Description
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m7xj-ccqc-p4g2 | Apache Tomcat Directory Traversal vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T09:21:34.503Z
Reserved: 2008-06-30T00:00:00.000Z
Link: CVE-2008-2938
No data.
Status : Deferred
Published: 2008-08-13T00:41:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2008-2938
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA