Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.7
- >= 10.1.0-M1, <= 10.1.41
- >= 9.0.0.M1, <= 9.0.105
An authentication bypass vulnerability has been identified in Apache Tomcat versions 11.0.0-M1 through 11.0.7, 10.1.0-M1 through 10.1.41, and 9.0.0.M1 through 9.0.105. This vulnerability arises when PreResources or PostResources are mounted outside the root of the web application, allowing access to these resources via an unexpected path. Such paths may not be subject to the same security constraints as the intended routes, potentially leading to a bypass of those security measures.
Exploitation of this vulnerability could allow unauthorized access to resources, bypassing established security constraints.
Users are advised to upgrade to Apache Tomcat 11.0.8, 10.1.42, or 9.0.106.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.