BIT-tomcat-2022-29885

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2022-29885.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2022-29885
Aliases
Published
2024-03-06T11:09:24.492Z
Modified
2024-03-11T19:11:34.914181Z
Summary
[none]
Details

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.38
Fixed
8.5.78
Introduced
9.0.13
Fixed
9.0.62
Introduced
10.0.0
Fixed
10.0.20
Type
SEMVER
Events
Introduced
10.1.0-milestone1
Last affected
10.1.0-milestone1
Introduced
10.1.0-milestone10
Last affected
10.1.0-milestone10
Introduced
10.1.0-milestone11
Last affected
10.1.0-milestone11
Introduced
10.1.0-milestone12
Last affected
10.1.0-milestone12
Introduced
10.1.0-milestone13
Last affected
10.1.0-milestone13
Introduced
10.1.0-milestone14
Last affected
10.1.0-milestone14
Introduced
10.1.0-milestone2
Last affected
10.1.0-milestone2
Introduced
10.1.0-milestone3
Last affected
10.1.0-milestone3
Introduced
10.1.0-milestone4
Last affected
10.1.0-milestone4
Introduced
10.1.0-milestone5
Last affected
10.1.0-milestone5
Introduced
10.1.0-milestone6
Last affected
10.1.0-milestone6
Introduced
10.1.0-milestone7
Last affected
10.1.0-milestone7
Introduced
10.1.0-milestone8
Last affected
10.1.0-milestone8
Introduced
10.1.0-milestone9
Last affected
10.1.0-milestone9