Apache Tomcat - XSS in generated JSPs
Moderate severity
GitHub Reviewed
Published
Nov 18, 2024
to the GitHub Advisory Database
•
Updated Nov 18, 2024
Package
Affected versions
= 11.0.0
= 10.1.31
= 9.0.96
Patched versions
11.0.1
10.1.32
9.0.97
Description
Published by the National Vulnerability Database
Nov 18, 2024
Published to the GitHub Advisory Database
Nov 18, 2024
Reviewed
Nov 18, 2024
Last updated
Nov 18, 2024
Description:
The fix for improvement 69333 caused pooled JSP tags not to be released after use which in turn could cause output of some tags not to escaped as expected. This unescaped output could lead to XSS.
Versions Affected:
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
Note: 10.1.32 was not released
References