Bug 237080 - (CVE-2007-0450) CVE-2007-0450 tomcat directory traversal
CVE-2007-0450 tomcat directory traversal
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All All
medium Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20070314,sour...
: Security
Depends On: 237086 237088 237089 237090 237109 238402 238574 240208 390331 390341 390351 390361 414311 430730 430731 449337 470236 470237
Blocks: 444136
  Show dependency treegraph
 
Reported: 2007-04-19 07:56 EDT by Mark J. Cox (Product Security)
Modified: 2012-02-23 02:22 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-02-23 02:22:30 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Mark J. Cox (Product Security) 2007-04-19 07:56:53 EDT
From http://tomcat.apache.org/security-5.html

Fixed in Apache Tomcat 5.5.22, 5.0.HEAD

Directory traversal CVE-2007-0450

Tomcat permits '\', '%2F' and '%5C' as path delimiters. When Tomcat is used
behind a proxy (including, but not limited to, Apache HTTP server with mod_proxy
and mod_jk) configured to only proxy some contexts, a HTTP request containing
strings like "/\../" may allow attackers to work around the context restriction
of the proxy, and access the non-proxied contexts.

The following Java system properties have been added to Tomcat to provide
additional control of the handling of path delimiters in URLs (both options
default to false):

      * org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH: true|false
      * org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH: true|false

Due to the impossibility to guarantee that all URLs are handled by Tomcat as
they are in proxy servers, Tomcat should always be secured as if no proxy
restricting context access was used.

Affects: 5.5.0-5.5.21, 5.0.0-5.0.30
Comment 4 Mark J. Cox (Product Security) 2007-04-23 06:39:57 EDT
Advisory text: "Tomcat permitted various characters as path delimiters.  If
Tomcat was used behind a certain proxies and configured to only proxy some
contexts, an attacker could construct a HTTP request to work around the context
restriction and potentially access non-proxied content.  (CVE-2007-0450)"
Comment 5 Jean-frederic Clere 2007-05-02 02:36:33 EDT
If the customer as an unsecure access to /jmx-console or /web-console running on
localhost and use mod_jk/mod_proxy an attack request could get access to them.
Comment 11 errata-xmlrpc 2010-08-04 17:32:29 EDT
This issue has been addressed in following products:

  Red Hat Certificate System 7.3

Via RHSA-2010:0602 https://rhn.redhat.com/errata/RHSA-2010-0602.html

Note You need to log in before you can comment on or make changes to this bug.