CVE-2012-4431Medium· 4.3▾ TwilightPoC availableorg/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a sessio…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 1.8 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.1%
1 GitHub repo (last check)
org/apache/catalina/filters/CsrfPreventionFilter.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.32 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism via a request that lacks a session identifier.
tomcat = 6.0tomcat = 6.0.0tomcat = 6.0.1tomcat = 6.0.2tomcat = 6.0.3tomcat = 6.0.4tomcat = 6.0.5tomcat = 6.0.6tomcat = 6.0.7tomcat = 6.0.8tomcat = 6.0.9tomcat = 6.0.10tomcat = 6.0.11tomcat = 6.0.12tomcat = 6.0.13tomcat = 6.0.14tomcat = 6.0.15tomcat = 6.0.16tomcat = 6.0.17tomcat = 6.0.18tomcat = 6.0.19tomcat = 6.0.20tomcat = 6.0.24tomcat = 6.0.26tomcat = 6.0.27tomcat = 6.0.28tomcat = 6.0.29tomcat = 6.0.30tomcat = 6.0.31tomcat = 6.0.32tomcat = 6.0.33tomcat = 6.0.35tomcat = 7.0.0tomcat = 7.0.1tomcat = 7.0.2tomcat = 7.0.3tomcat = 7.0.4tomcat = 7.0.5tomcat = 7.0.6tomcat = 7.0.7tomcat = 7.0.8tomcat = 7.0.9tomcat = 7.0.10tomcat = 7.0.11tomcat = 7.0.12tomcat = 7.0.13tomcat = 7.0.14tomcat = 7.0.15tomcat = 7.0.16tomcat = 7.0.17tomcat = 7.0.18tomcat = 7.0.19tomcat = 7.0.20tomcat = 7.0.21tomcat = 7.0.22tomcat = 7.0.23tomcat = 7.0.25tomcat = 7.0.28tomcat = 7.0.30Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2012-5885Medium· 5.0The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka …
CVE-2013-4322Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a …
CVE-2013-4590Medium· 4.3Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, o…
CVE-2013-4286Medium· 5.8Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incor…
CVE-2012-3544Medium· 5.0Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
CVE-2013-2067Medium· 6.8java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements …