Apache Tomcat Allows Source Disclosure
Moderate severity
GitHub Reviewed
Published
Apr 30, 2022
to the GitHub Advisory Database
•
Updated Sep 18, 2023
Package
Affected versions
< 3.2.2
Patched versions
3.2.2
Description
Published by the National Vulnerability Database
Aug 2, 2001
Published to the GitHub Advisory Database
Apr 30, 2022
Reviewed
Sep 18, 2023
Last updated
Sep 18, 2023
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
References