{"id":"GHSA-p26v-97vp-jcx6","summary":"Access controll bypass in Apache Tomcat","details":"Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.","aliases":["CVE-2011-1183"],"modified":"2024-02-21T21:04:02Z","published":"2022-05-14T02:56:10Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-02-14T00:43:50Z","nvd_published_at":"2011-04-08T15:17:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1183"},{"type":"WEB","url":"https://github.com/apache/tomcat/commit/b7b5c63a932f6c1ea05f9b65ad9054247bb5af57"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/66675"},{"type":"PACKAGE","url":"https://github.com/apache/tomcat"},{"type":"WEB","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12701"},{"type":"WEB","url":"https://web.archive.org/web/20200229122300/http://www.securityfocus.com/bid/47196"},{"type":"WEB","url":"https://web.archive.org/web/20200928033804/http://www.securityfocus.com/archive/1/517362/100/0/threaded"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2011/Apr/96"},{"type":"WEB","url":"http://securityreason.com/securityalert/8187"},{"type":"WEB","url":"http://svn.apache.org/viewvc?view=revision&revision=1087643"},{"type":"WEB","url":"http://tomcat.apache.org/security-7.html"}],"affected":[{"package":{"name":"org.apache.tomcat:tomcat","ecosystem":"Maven","purl":"pkg:maven/org.apache.tomcat/tomcat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.11"},{"fixed":"7.0.12"}]}],"versions":["7.0.11"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-p26v-97vp-jcx6/GHSA-p26v-97vp-jcx6.json"}}],"schema_version":"1.9.0"}