Skip to main content
x

Apache Tomcat version 6.0.21 မှ 6.0.36 အထိ နှင့် version 7.0.33 မတိုင်မီ

Apache Tomcat version 6.0.21 မှ 6.0.36 အထိ နှင့် version 7.0.33 မတိုင်မီ version 7.x များတွင် authentication feature form မှ java/org/apache/catalina/authenticator/FormAuthenticator.java သည် authentication requirements နှင့် sessions များကြား လုပ်ဆောင်မှုများကို handle မလုပ်နိုင်တော့ပါ။ ထိုအားနည်းချက်ကြောင့် Remote Attacker များသည် အမျိုးမျိုးသော session fixation attack ကို သုံးပြီး Login Form Completion လုပ်နေစဥ်အတွင်း victim ရဲ့ credentials များကို သုံး၍ လက်ရှိ session ထဲသို့ injection လုပ်၍ ရနေပါသည်။ ထို့ကြောင့် version 7.0.33 တွင် ၄င်းကို Fix လုပ်ထားကြောင်း Apache Tomcat မှ ၂ဝ၁၃ခုနှစ်၊ မေလ (၁ဝ)ရက်နေ့တွင် ထုတ်ပြန်ထားပါသည်။ အသေးစိတ်ကို အောက်ပါ Link တွင် ကြည့်ရှုနိုင်ပါသည်။

http://tomcat.apache.org/security-7.html