Skip to content

Improper Authentication in Apache Tomcat

Moderate severity GitHub Reviewed Published May 2, 2022 to the GitHub Advisory Database • Updated Feb 21, 2024

Package

maven org.apache.tomcat:tomcat (Maven)

Affected versions

>= 5.5.0, <= 5.5.28
>= 6.0.0, < 6.0.24

Patched versions

5.5.29
6.0.24

Description

The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

References

Published by the National Vulnerability Database Jan 28, 2010
Published to the GitHub Advisory Database May 2, 2022
Reviewed Jun 17, 2022
Last updated Feb 21, 2024

Severity

Moderate

EPSS score

0.284%
(69th percentile)

Weaknesses

CVE ID

CVE-2009-2901

GHSA ID

GHSA-hjfh-7c4v-7q8h

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.