[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-903 ---- tomcat7 tomcat8

ID: oval:org.secpod.oval:def:1600778Date: (C)2017-10-04   (M)2017-10-12
Class: PATCHFamily: unix




1480618: Vary header not added by CORS filter leading to cache poisoningThe CORS Filter in Apache Tomcat did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances

Platform:
Amazon Linux AMI
Product:
tomcat7
tomcat8
Reference:
ALAS-2017-903
CVE-2017-7674
CVE    1
CVE-2017-7674
CPE    46
cpe:/a:apache:tomcat8
cpe:/a:apache:tomcat7
cpe:/a:apache:tomcat:7.0.62
cpe:/a:apache:tomcat:7.0.61
...

© 2013 SecPod Technologies