Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat

GHSA-87w9-x2c3-hrjj · CVE-2013-4590

Published · Modified

Description

Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes