You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Vulnerable Package issue exists @ Maven-org.apache.tomcat:tomcat-catalina-7.0.27 in branch main
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 7.0.X Before 7.0.109, 8.X before 8.5.66, 9.0.X before 9.0.46, and before 10.0.6.
Vulnerable Package issue exists @ Maven-org.apache.tomcat:tomcat-catalina-7.0.27 in branch main
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 7.0.X Before 7.0.109, 8.X before 8.5.66, 9.0.X before 9.0.46, and before 10.0.6.
Namespace: cxronen
Repository: AST_BookStore
Repository Url: https://github.com/cxronen/AST_BookStore
CxAST-Project: cxronen/AST_BookStore
CxAST platform scan: 1dfa7500-ca95-4ace-923f-3cf597ff6d1c
Branch: main
Application: AST_BookStore
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-287
Additional Info
Attack vector: NETWORK
Attack complexity: HIGH
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 7.0.109
References
Advisory
Mail Thread
Issue
Commit
Commit
Commit
Commit
Commit
Commit
Commit
Commit
Issue
The text was updated successfully, but these errors were encountered: