[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3974-1 tomcat8 -- tomcat8

ID: oval:org.secpod.oval:def:70590Date: (C)2021-04-01   (M)2023-12-14
Class: PATCHFamily: unix




Two issues were discovered in the Tomcat servlet and JSP engine. CVE-2017-7674 Rick Riemer discovered that the Cross-Origin Resource Sharing filter did not add a Vary header indicating possible different responses, which could lead to cache poisoning. CVE-2017-7675 Markus D#xF6;rschmidt found that the HTTP/2 implementation bypassed some security checks, thus allowing an attacker to conduct directory traversal attacks by using specially crafted URLs.

Platform:
Linux Mint 3
Product:
tomcat8
Reference:
DSA-3974-1
CVE-2017-7674
CVE-2017-7675
CVE    2
CVE-2017-7675
CVE-2017-7674

© SecPod Technologies