Back

MEDIUM

tomcat: XSS in SSI printenv

Published May 28, 2019

Description

The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.

Affected products

Remediation

Red Hat mitigation

SSI is disabled in the default Tomcat configuration. The vulnerable printenv command is intended for debugging, and is recommended to not be enabled for a production website.

Metrics

References (51)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 28, 2019
Updated Aug 4, 2024
Reserved Nov 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 13, 2019
GHSA-JJPQ-GP5Q-8Q6W