You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
mend-for-github-combot
changed the title
CVE-2013-4590 (Medium) detected in tomcat-catalina-7.0.42.jar
CVE-2013-4590 (Medium) detected in tomcat-catalina-7.0.42.jar, tomcat-util-7.0.42.jar
Mar 25, 2021
mend-for-github-combot
changed the title
CVE-2013-4590 (Medium) detected in tomcat-catalina-7.0.42.jar, tomcat-util-7.0.42.jar
CVE-2013-4590 (Low) detected in tomcat-catalina-7.0.42.jar, tomcat-util-7.0.42.jar
Dec 14, 2021
CVE-2013-4590 - Low Severity Vulnerability
Vulnerable Libraries - tomcat-catalina-7.0.42.jar, tomcat-util-7.0.42.jar
tomcat-catalina-7.0.42.jar
Tomcat Servlet Engine Core Classes and Standard implementations
Library home page: http://tomcat.apache.org/
Path to dependency file: /pom.xml
Path to vulnerable library: /repository/org/apache/tomcat/tomcat-catalina/7.0.42/tomcat-catalina-7.0.42.jar
Dependency Hierarchy:
tomcat-util-7.0.42.jar
Common code shared by Catalina and Jasper
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/tomcat/tomcat-util/7.0.42/tomcat-util-7.0.42.jar
Dependency Hierarchy:
Found in HEAD commit: 630f758cd843b129965c1658c5baf81a8deff375
Found in base branches: dev, master
Vulnerability Details
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Publish Date: 2014-02-26
URL: CVE-2013-4590
CVSS 3 Score Details (3.7)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4590
Release Date: 2014-02-26
Fix Resolution (org.apache.tomcat:tomcat-util): 7.0.50
Direct dependency fix Resolution (org.apache.tomcat:tomcat-catalina): 7.0.50
⛑️ Automatic Remediation is available for this issue
The text was updated successfully, but these errors were encountered: