Description
When using a VirtualDirContext it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.
Remediation
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 7.0.81
References
Related Vulnerabilities
WordPress Plugin MAC PHOTO GALLERY 'albid' Parameter Arbitrary File Disclosure (2.8)
InfluxDB Unauthorized Access Vulnerability
WordPress 4.9.x Multiple Vulnerabilities (4.9 - 4.9.23)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4999)
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-7060)