-
CVSS Score
-A Semantic Attack on Google Gemini - Read the Latest Research
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.apache.tomcat:tomcat | maven | = 9.0.0.M1 | 9.0.0.M2 |
| org.apache.tomcat:tomcat | maven | >= 8.0.0.RC1, < 8.0.32 | 8.0.32 |
| org.apache.tomcat:tomcat | maven | >= 7.0.0, < 7.0.70 | 7.0.70 |
| org.apache.tomcat:tomcat | maven | >= 6.0.0, < 6.0.46 | 6.0.46 |
The analysis focused on identifying functions directly related to the session attribute filtering and handling, which are central to the CVE-2016-0714 vulnerability. The patches indicate that the ManagerBase class was modified to include new filtering mechanisms and logging controls, which are critical to mitigating the vulnerability.