Incorrect Authorization in Apache Tomcat
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 23, 2024
Package
Affected versions
>= 9.0.0.M1, <= 9.0.0.M9
>= 8.5.0, <= 8.5.4
>= 8.0.0, <= 8.0.36
>= 7.0.0, < 7.0.72
Patched versions
9.0.0.M10
8.5.5
8.0.37
7.0.72
Description
Published by the National Vulnerability Database
Aug 10, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 6, 2022
Last updated
Feb 23, 2024
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
References