|
Apache Tomcat 'allowLinking' Accepts NULL Byte in URI Information Disclosure Vulnerability
Apache Tomcat is prone to a remote information-disclosure vulnerability because the HTTP/1.0 connector fails to properly handle a NULL byte in URIs when 'allowLinking' is configured. Remote attackers can exploit this issue to obtain potentially sensitive information. Note that HTTP/1.0 connector is deprecated; this issue is not scheduled to be fixed. The issue affects Tomcat 4.1.15 and later. |
|
|
Privacy Statement |