CVE Published: 04/10/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2018 Source: apache |
Vendor: Apache Software Foundation |
Product: Apache Tomcat Status : PUBLISHED
CVE-2018-11784 Description
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to \'/foo/\' when the user requested \'/foo\') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.