{"id":"GHSA-5hgm-qm5m-5vmw","summary":"Jakarta Tomcat cross-site scripting (XSS) vulnerability","details":"Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.","aliases":["CVE-2003-0044"],"modified":"2023-11-08T03:56:45.101873Z","published":"2022-04-29T01:25:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-09-18T22:43:30Z","nvd_published_at":"2003-02-07T05:00:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0044"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11196"},{"type":"WEB","url":"http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a"},{"type":"WEB","url":"http://jakarta.apache.org/builds/jakarta-tomcat/release/v3.3.1a/RELEASE-NOTES-3.3.1a.txt"},{"type":"WEB","url":"http://secunia.com/advisories/7972"},{"type":"WEB","url":"http://www.ciac.org/ciac/bulletins/n-060.shtml"},{"type":"WEB","url":"http://www.debian.org/security/2003/dsa-246"},{"type":"WEB","url":"http://www.osvdb.org/9203"},{"type":"WEB","url":"http://www.osvdb.org/9204"},{"type":"WEB","url":"http://www.securityfocus.com/advisories/5111"},{"type":"WEB","url":"http://www.securityfocus.com/bid/6720"}],"affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0"},{"fixed":"3.3.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.3.1a","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-5hgm-qm5m-5vmw/GHSA-5hgm-qm5m-5vmw.json"}}],"schema_version":"1.9.0"}