Back

LOW

tomcat: World-readable log directory

Published Feb 15, 2014

Description

Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

Affected products

Remediation

Red Hat statement

Red Hat does not regard this to be a security flaw. The tomcat log directory does not contain any sensitive information, and when sensitive information has been written to log files, this has been considered a security flaw in tomcat (e.g. CVE-2011-2204). This issue was reported to the Apache Tomcat project, and they have not considered it a flaw in any published security advisories.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 15, 2014
Updated Aug 6, 2024
Reserved Dec 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 22, 2013