www-announce mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Mark Thomas <ma...@apache.org>
Subject [SECURITY] CVE-2017-12615 Apache Tomcat Remote Code Execution via JSP upload
Date Tue, 19 Sep 2017 10:58:44 GMT
CVE-2017-7674 Apache Tomcat Remote Code Execution via JSP Upload

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 7.0.0 to 7.0.79

When running on Windows with HTTP PUTs enabled (e.g. via setting the
readonly initialisation parameter of the Default to false) it was
possible to upload a JSP file to the server via a specially crafted
request. This JSP could then be requested and any code it contained
would be executed by the server.

Users of the affected versions should apply one of the following
- Upgrade to Apache Tomcat 7.0.81 or later (7.0.80 was not released)

This issue was reported responsibly to the Apache Tomcat Security Team
by iswin from 360-sg-lab (360观星实验室)

2017-09-19 Original advisory

[1] http://tomcat.apache.org/security-7.html

View raw message