Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Apache Tomcat Mishandles Character Sequence in Cookies

GHSA-6j8f-66vh-39mj · CVE-2007-3385

Published · Modified

Description

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes