​
DirectorySecurity Advisories
Sign In
Security Advisories

CGA-76c4-v9xm-9m69

Published

Last updated

https://images.chainguard.dev/security/CGA-76c4-v9xm-9m69
Package

spark-3.5.0-compat

Latest Update
Fixed
Fixed Version

3.5.0-r2

Aliases
  • CVE-2019-17563
  • GHSA-9xcj-c8cr-8c3c

Severity

7.5

High

CVSS V3

Summary

In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack

Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images