Apache Tomcat Directory Traversal
Moderate severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 8, 2024
Package
Affected versions
>= 5.0, < 5.5.22
>= 6.0, < 6.0.10
Patched versions
5.5.22
6.0.10
Description
Published by the National Vulnerability Database
Mar 16, 2007
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Sep 21, 2023
Last updated
Jan 8, 2024
Directory traversal vulnerability in Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a
..
(dot dot) sequence with combinations of (1)/
(slash), (2)\
(backslash), and (3) URL-encoded backslash (%5C
) characters in the URL, which are valid separators in Tomcat but not in Apache.References