/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2019-17563

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2019-17563

CGA ID

CGA-76c4-v9xm-9m69

Severity

7.5

High

CVSS V3

Description

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs