| CNNVD-ID编号 | CNNVD-201905-794 | CVE编号 | CVE-2019-0221 |
| 发布时间 | 2019-05-17 | 更新时间 | 2020-09-24 |
| 漏洞类型 | 跨站脚本 | 漏洞来源 | Nightwatch Cybersecurity Research.,Debian,Red Hat,Gentoo |
| 危险等级 | 中危 | 威胁类型 | 远程 |
| 厂商 | N/A | ||
Apache Tomcat是美国阿帕奇(Apache)软件基金会的一款轻量级Web应用服务器。该程序实现了对Servlet和JavaServer Page(JSP)的支持。
Apache Tomcat 9.0.0.M1版本至9.0.0.17版本、8.5.0版本至8.5.39版本和7.0.0版本至7.0.93版本中存在跨站脚本漏洞。该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
目前厂商已发布升级了Apache Tomcat 跨站脚本漏洞的补丁,Apache Tomcat 跨站脚本漏洞的补丁获取链接:
http://mail-archives.apache.org/mod_mbox/www-announce/201905.mbox/%3Cb1905aa6-f340-8d0b-58c4-8ac3ebcbfa54@apache.org%3E
来源:lists.apache.org
来源:wwws.nightwatchcybersecurity.com
来源:seclists.org
来源:github.com
来源:github.com
来源:github.com
来源:tomcat.apache.org
来源:FULLDISC
来源:BID
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/05/msg00044.html
来源:CONFIRM
来源:access.redhat.com
来源:access.redhat.com
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191866-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191895-1.html
来源:www.debian.org
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191693-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155415/Red-Hat-Security-Advisory-2019-3929-01.html
来源:www.auscert.org.au
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Apache-Tomcat-Cross-Site-Scripting-via-SSI-printenv-29350
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156827/Gentoo-Linux-Security-Advisory-202003-43.html
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155792/Debian-Security-Advisory-4596-1.html
来源:www.auscert.org.au
来源:www.ibm.com
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.auscert.org.au
来源:www.securityfocus.com
来源:nvd.nist.gov
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/156781/Red-Hat-Security-Advisory-2020-0861-01.html
暂无