An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS02ajhmLTY2dmgtMzltas2iMA

Moderate EPSS: 0.69407% (0.98549 Percentile) EPSS:

Apache Tomcat Mishandles Character Sequence in Cookies

Affected Packages Affected Versions Fixed Versions
maven:org.apache.tomcat:tomcat >= 3.3.0, <= 3.3.2, >= 4.1.0, <= 4.1.36, >= 5.0.0, <= 5.0.30, >= 5.5.0, <= 5.5.24, >= 6.0.0, <= 6.0.13 No known fixed version
30 Dependent packages
438 Dependent repositories

Affected Version Ranges

All affected versions

Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.

References: