CVE-2013-2067
Improper Authentication in Apache Tomcat
EPSS 7.1%
描述
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
如何修補 CVE-2013-2067
要修補 CVE-2013-2067,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.tomcat:tomcat—升級至 6.0.37 或更新版本
CVE-2013-2067 正在被利用嗎?
中等 — EPSS 為 7.1%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 6.0.21, < 6.0.37