-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.tomcat:tomcat-catalina | maven | >= 5.5.0, < 5.5.36 | 5.5.36 |
| org.apache.tomcat:tomcat-catalina | maven | >= 6.0.0, < 6.0.36 | 6.0.36 |
| org.apache.tomcat:tomcat-catalina | maven | >= 7.0.0, < 7.0.30 | 7.0.30 |
The vulnerability stems from DigestAuthenticator's session caching and weak nonce handling. The authenticate() method stored user credentials in the session (visible in patch removal of this behavior), while parseDigest() had insufficient validation of authentication parameters. Runtime detection would show these functions processing authentication requests with vulnerable session linkage.
Ongoing coverage of React2Shell