CVE-2014-0033
Publication date 26 February 2014
Last updated 24 July 2024
Ubuntu priority
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does not consider the disableURLRewriting setting when handling a session ID in a URL, which allows remote attackers to conduct session fixation attacks via a crafted URL.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat6 | 14.04 LTS trusty |
Not affected
|
tomcat7 | 14.04 LTS trusty |
Not affected
|
Notes
Patch details
Package | Patch details |
---|---|
tomcat6 |
References
Related Ubuntu Security Notices (USN)
- USN-2130-1
- Tomcat vulnerabilities
- 6 March 2014