CVE-2020-1938
CRITICALWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomca
- Affected
- >=7.0.0, <7.0.100, >=8.5.0, <8.5.51, >=9.0.0, <9.0.31
- Fixed in
- not stated
- Published
- 2020-02-24
- Source
- NVD