Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Tomcat 'allowLinking'接受URI空字节信息泄露漏洞
Vulnerability Description
Apache Tomcat 4.1.15及其后续版本中的HTTP/1.1 connector在配置了allowLinking时并未在URL中注入空字节,因此,远程攻击者可以读取JSP源文件并获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A