diff --git a/advisories/unreviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json b/advisories/github-reviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json similarity index 63% rename from advisories/unreviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json rename to advisories/github-reviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json index 0afca8c719e..2a46cfa5b49 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json +++ b/advisories/github-reviewed/2022/05/GHSA-f7w7-6pjc-wwm6/GHSA-f7w7-6pjc-wwm6.json @@ -1,23 +1,112 @@ { "schema_version": "1.4.0", "id": "GHSA-f7w7-6pjc-wwm6", - "modified": "2022-05-02T03:46:22Z", + "modified": "2024-02-22T19:39:26Z", "published": "2022-05-02T03:46:22Z", "aliases": [ "CVE-2009-3555" ], - "details": "The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a \"plaintext injection\" attack, aka the \"Project Mogul\" issue.", + "summary": "Apache Tomcat affected by vulnerability in TLS and SSL protocol", + "details": "The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a \"plaintext injection\" attack, aka the \"Project Mogul\" issue.\n\nApache Tomcat was affected by this issue and introduced a workaround in versions 7.0.10, 6.0.32, and 5.5.33.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0.0" + }, + { + "fixed": "7.0.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.0.0" + }, + { + "fixed": "6.0.32" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.tomcat:tomcat" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0" + }, + { + "fixed": "5.5.33" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3555" }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/14e4efd925da58b9fa63f20969fb7349b8a9c30d" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/2d4ca03acc27cc883c404d1745d92f983b6fada3" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/30af3f5630542a2340781f66553e734a6fd69701" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/328a523cbb2a2d4cd55283180614d4e03e2f8f02" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/3d315ac9dfaa2c03b4df82938d78bf5b755766b3" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/56f67141e82e16f68a860c3af9b7342da35cbe7d" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/b4e9488629bf03b4b65abf335e536e85386d1366" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/df9633116b5fec8f47f1f008fb89a6e9d5895cd0" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2009:1579" @@ -142,6 +231,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=533125" }, + { + "type": "WEB", + "url": "https://bz.apache.org/bugzilla/show_bug.cgi?id=50325" + }, { "type": "WEB", "url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049" @@ -150,6 +243,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/54158" }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/tomcat" + }, { "type": "WEB", "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888" @@ -160,67 +257,51 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E" + "url": "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E" + "url": "https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2@" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E" + "url": "https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220@" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2@%3Cdev.tomcat.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d@" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:10088" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220@%3Cdev.tomcat.apache.org%3E" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:11578" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:11617" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d@%3Cdev.tomcat.apache.org%3E" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:7315" }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:7478" }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:7973" }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:8366" }, { "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315" - }, - { - "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478" - }, - { - "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973" - }, - { - "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366" - }, - { - "type": "WEB", - "url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535" + "url": "https://oval.cisecurity.org/repository/search/definition/oval:org.mitre.oval:def:8535" }, { "type": "WEB", @@ -230,6 +311,18 @@ "type": "WEB", "url": "https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt" }, + { + "type": "WEB", + "url": "https://tomcat.apache.org/security-5.html" + }, + { + "type": "WEB", + "url": "https://tomcat.apache.org/security-6.html" + }, + { + "type": "WEB", + "url": "https://tomcat.apache.org/security-7.html" + }, { "type": "WEB", "url": "https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html" @@ -438,242 +531,10 @@ "type": "WEB", "url": "http://openbsd.org/errata46.html#004_openssl" }, - { - "type": "WEB", - "url": "http://osvdb.org/60521" - }, - { - "type": "WEB", - "url": "http://osvdb.org/60972" - }, - { - "type": "WEB", - "url": "http://osvdb.org/62210" - }, - { - "type": "WEB", - "url": "http://osvdb.org/65202" - }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2009/Nov/139" }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37291" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37292" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37320" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37383" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37399" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37453" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37501" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37504" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37604" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37640" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37656" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37675" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/37859" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38003" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38020" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38056" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38241" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38484" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38687" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38781" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39127" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39136" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39242" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39243" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39278" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39292" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39317" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39461" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39500" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39628" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39632" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39713" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/39819" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/40070" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/40545" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/40747" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/40866" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/41480" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/41490" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/41818" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/41967" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/41972" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42377" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42379" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42467" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42724" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42733" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42808" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42811" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/42816" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/43308" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/44183" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/44954" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/48577" - }, { "type": "WEB", "url": "http://security.gentoo.org/glsa/glsa-200912-01.xml" @@ -686,10 +547,6 @@ "type": "WEB", "url": "http://security.gentoo.org/glsa/glsa-201406-32.xml" }, - { - "type": "WEB", - "url": "http://securitytracker.com/id?1023148" - }, { "type": "WEB", "url": "http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446" @@ -1010,154 +867,6 @@ "type": "WEB", "url": "http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html" }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/507952/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/508075/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/508130/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/515055/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/516397/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/522176" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/36935" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023163" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023204" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023205" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023206" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023207" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023208" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023209" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023210" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023211" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023212" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023213" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023214" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023215" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023216" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023217" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023218" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023219" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023224" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023243" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023270" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023271" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023272" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023273" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023274" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023275" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023411" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023426" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023427" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1023428" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id?1024789" - }, { "type": "WEB", "url": "http://www.tombom.co.uk/blog/?p=85" @@ -1197,146 +906,6 @@ { "type": "WEB", "url": "http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3164" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3165" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3205" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3220" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3310" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3313" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3353" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3354" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3484" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3521" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/3587" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0086" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0173" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0748" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0848" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0916" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0933" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0982" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/0994" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1054" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1107" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1191" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1350" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1639" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1673" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1793" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/2010" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/2745" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/3069" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/3086" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/3126" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2011/0032" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2011/0033" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2011/0086" - }, - { - "type": "WEB", - "url": "http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html" } ], "database_specific": { @@ -1344,8 +913,8 @@ "CWE-295" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-02-22T19:39:23Z", "nvd_published_at": "2009-11-09T17:30:00Z" } } \ No newline at end of file