Answer in brief
CVE-2005-2090 records a Unknown severity security vulnerability in Tomcat Vulnerable to Web Cache Poisoning. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Answer in brief
CVE-2005-2090 records a Unknown severity security vulnerability in Tomcat Vulnerable to Web Cache Poisoning. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Monitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2005-2090 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat:tomcatmaven | >=5.0.0 | Not reported |
| org.apache.tomcat:tomcatmaven | >=4.0.0 | Not reported |
Reported by OSV (osv).
CVE-2005-2090 records a Unknown severity security vulnerability in Tomcat Vulnerable to Web Cache Poisoning. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for org.apache.tomcat:tomcat, org.apache.tomcat:tomcat.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardMonitor this advisory for an available fix and review any installs of the affected package.
Local check
hol-guard supply-chain scanVulnerability describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2005-2090 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat:tomcatmaven | >=5.0.0 | Not reported |
| org.apache.tomcat:tomcatmaven | >=4.0.0 | Not reported |
Reported by OSV (osv).
CVE-2005-2090 records a Unknown severity security vulnerability in Tomcat Vulnerable to Web Cache Poisoning. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for org.apache.tomcat:tomcat, org.apache.tomcat:tomcat.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardJakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."