发布时间: 2024年1月30日
修改时间: 2024年10月31日
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43.Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
NVD | openEuler | |
---|---|---|
Confidentiality | Low | High |
Attack Vector | Network | Network |
CVSS评分 | 5.3 | 7.5 |
Attack Complexity | Low | Low |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | None | None |
User Interaction | None | None |
Availability | None | None |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-1068 | tomcat security update | 2024年1月30日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-4A | tomcat | Fixed |
KY3.4-5 | tomcat | Fixed |
KY3.5.1 | tomcat | Fixed |
KY3.5.2 | tomcat | Fixed |