PT-2020-20935 · Apache+2 · Apache Tomcat+2

Ilja Brander

·

Published

2020-11-17

·

Updated

2026-03-26

·

CVE-2021-24122

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 7.0.0 through 7.0.106 Apache Tomcat versions 8.5.0 through 8.5.59 Apache Tomcat versions 9.0.0.M1 through 9.0.39 Apache Tomcat versions 10.0.0-M1 through 10.0.0-M9
Description When serving resources from a network location using the NTFS file system, Apache Tomcat was susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behavior of the JRE API File.getCanonicalPath(), which in turn was caused by the inconsistent behavior of the Windows API (FindFirstFileW) in some circumstances.
Recommendations For Apache Tomcat versions 7.0.0 through 7.0.106, update to a version that includes the fix for this issue. For Apache Tomcat versions 8.5.0 through 8.5.59, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.0.M1 through 9.0.39, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.0.0-M1 through 10.0.0-M9, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to JSP files served from network locations using the NTFS file system until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1993
ALT-PU-2025-9146
BIT-TOMCAT-2021-24122
CVE-2021-24122
DLA-2594-1
GHSA-2RVV-W9R2-RG7M
MGASA-2021-0072
OESA-2021-1075
OPENSUSE-SU-2021:0330-1
OPENSUSE-SU-2021_0330-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2021:0494
ROSA-SA-2023-2258
SUSE-SU-2021:0530-1
SUSE-SU-2021:0531-1
SUSE-SU-2021:0989-1
SUSE-SU-2021:1009-1
SUSE-SU-2021:14705-1
SUSE-SU-2021_0530-1
SUSE-SU-2021_0531-1
SUSE-SU-2021_14705-1
SUSE-SU-2026:1058-1

Affected Products

Alt Linux
Apache Tomcat
Suse