Back

HIGH

tomcat: Information Disclosure when using VirtualDirContext

Published Sep 19, 2017

Description

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

Affected products

Remediation

Red Hat statement

VirtualDirContext is not designed to be used in production, but only to ease development with IDEs without needing to fully republish jars in WEB-INF/lib.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 19, 2017
Updated Sep 16, 2024
Reserved Aug 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 19, 2017
GHSA-8QQ4-8JVQ-MFW4