5.9mediumMedium

CVE-2021-24122

Apache Tomcat

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was caused by the inconsistent behaviour of the Windows API (FindFirstFileW) in some circumstances.

Exploitation status

  • A vendor advisory or patch reference has been published.

What the metrics mean

  • It is reachable over a network, without needing local access.
  • For an attacker who can reach it, exploitation depends on conditions outside the attacker's control.
  • To exploit it, no account is needed.
  • Beyond that, no action by a user is required.

Scoring

CVSS
5.9 (v3.1)
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness
CWE-200
Assigned by
security@apache.org

Dates

Published
2021-01-14
Last modified
2026-08-25
Sources
NVD

Affected products

  • Apache Tomcat7.0.0 - 7.0.106, 8.5.0 - 8.5.59, 9.0.1 - 9.0.39, 9.0.0, 10.0.0
  • Debian Debian Linux9.0
  • Oracle Agile Product Lifecycle Management9.3.3, 9.3.6

As listed in the NVD configuration data. Not a statement about your estate.

References