CVE-2010-1157
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
EPSS 52.5%
描述
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
如何修補 CVE-2010-1157
要修補 CVE-2010-1157,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 5.5.30 或更新版本
CVE-2010-1157 正在被利用嗎?
可能 — EPSS 為 52.5%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 5.5.0, < 5.5.30