tomcat-embed-core is vulnerable to Improper Authorization
59
Medium Risk
tomcat-embed-core treats security-role-ref entries as Realm role aliases as well as the intended Request.isUserInRole() mapping. A user who holds only the referenced role name can satisfy a declarative role constraint they should not pass. That weakens web.xml role checks that rely on those references. The fix stops the Realm from using security-role-ref as an alias.
You are affected if you are using a version that falls within the vulnerable range and the application defines security-role-ref aliases.
tomcat-embed-core is vulnerable to Improper Authorization in versions 7.0.97 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.
Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.