Potential remote code execution in Apache Tomcat
High severity
GitHub Reviewed
Published
Mar 19, 2021
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
>= 10.0.0-M1, < 10.0.2
>= 9.0.0, < 9.0.41
>= 8.0.0, < 8.5.61
>= 7.0.0, < 7.0.107
Patched versions
10.0.2
9.0.41
8.5.61
7.0.108
Description
Published by the National Vulnerability Database
Mar 1, 2021
Reviewed
Mar 19, 2021
Published to the GitHub Advisory Database
Mar 19, 2021
Last updated
Feb 3, 2023
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously published mitigations for CVE-2020-9484 also apply to this issue.
References