CVE-2008-2370
Apache Tomcat Path Traversal Vulnerability
EPSS 52.7%
描述
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a `RequestDispatcher` is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a `..` (dot dot) in a request parameter.
如何修補 CVE-2008-2370
要修補 CVE-2008-2370,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 4.1.38 或更新版本
CVE-2008-2370 正在被利用嗎?
可能 — EPSS 為 52.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 4.1.0, < 4.1.38