Post

Apache Tomcat AJP file contains vulnerability CVE-2020-1938

Apache Tomcat AJP file contains vulnerability CVE-2020-1938

Apache Tomcat AJP file contains vulnerabilities CVE-2020-1938

Vulnerability Description

Java is the most mainstream programming language in web development, and Tomcat is one of the most popular Java middleware servers. It has a history of more than 20 years since its initial release and is widely used worldwide.

Affect Version

Apache Tomcat 6

Apache Tomcat 7 < 7.0.100

Apache Tomcat 8 < 8.5.51

Apache Tomcat 9 < 9.0.31

Environment construction

1
2
3
git clone https://github.com/vulhub/vulhub.git
cd vulhub/tomcat/CVE-2020-1938
docker-compose up -d

img

Vulnerability reappears

</a-alert>


img

This post is licensed under CC BY 4.0 by the author.