CVE-2011-2526
Improper Input Validation in Apache Tomcat
EPSS 0.70%
描述
Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.
如何修補 CVE-2011-2526
要修補 CVE-2011-2526,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 5.5.34 或更新版本
CVE-2011-2526 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 5.5.34