Description
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-91-1 | tomcat6 security update |
Debian DSA |
DSA-3530-1 | tomcat6 security update |
EUVD |
EUVD-2022-3142 | Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Github GHSA |
GHSA-87w9-x2c3-hrjj | Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:45:15.235Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4590
No data.
Status : Deferred
Published: 2014-02-26T14:55:08.207
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-4590
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA