CVE-2008-3271
published 2008-10-13CVE-2008-3271: Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
4.81%
91.0th percentile
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat RemoteFilterValve Information disclosure
vendor_redhat·2008-10-09·CVSS 4.3
CVE-2008-3271 [MEDIUM] tomcat RemoteFilterValve Information disclosure
tomcat RemoteFilterValve Information disclosure
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
GHSA
GHSA-5jpg-mjvg-hfhp: Apache Tomcat 5
ghsa_unreviewed·2022-05-01
CVE-2008-3271 [MEDIUM] GHSA-5jpg-mjvg-hfhp: Apache Tomcat 5
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
No detection rules found.
No public exploits indexed.
http://jvn.jp/en/jp/JVN30732239/index.htmlhttp://jvndb.jvn.jp/en/contents/2008/JVNDB-2008-000069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00012.htmlhttp://secunia.com/advisories/32213http://secunia.com/advisories/32234http://secunia.com/advisories/32398http://secunia.com/advisories/35684http://securityreason.com/securityalert/4396http://tomcat.apache.org/security-4.htmlhttp://tomcat.apache.org/security-5.htmlhttp://www.fujitsu.com/global/support/software/security/products-f/interstage-200806e.htmlhttp://www.nec.co.jp/security-info/secinfo/nv09-006.htmlhttp://www.securityfocus.com/archive/1/497220/100/0/threadedhttp://www.securityfocus.com/bid/31698http://www.securitytracker.com/id?1021039http://www.vupen.com/english/advisories/2008/2793http://www.vupen.com/english/advisories/2008/2800http://www.vupen.com/english/advisories/2009/1818https://exchange.xforce.ibmcloud.com/vulnerabilities/45791https://issues.apache.org/bugzilla/show_bug.cgi?id=25835https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3Ehttp://jvn.jp/en/jp/JVN30732239/index.htmlhttp://jvndb.jvn.jp/en/contents/2008/JVNDB-2008-000069.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00012.htmlhttp://secunia.com/advisories/32213http://secunia.com/advisories/32234http://secunia.com/advisories/32398http://secunia.com/advisories/35684http://securityreason.com/securityalert/4396http://tomcat.apache.org/security-4.htmlhttp://tomcat.apache.org/security-5.htmlhttp://www.fujitsu.com/global/support/software/security/products-f/interstage-200806e.htmlhttp://www.nec.co.jp/security-info/secinfo/nv09-006.htmlhttp://www.securityfocus.com/archive/1/497220/100/0/threadedhttp://www.securityfocus.com/bid/31698http://www.securitytracker.com/id?1021039http://www.vupen.com/english/advisories/2008/2793http://www.vupen.com/english/advisories/2008/2800http://www.vupen.com/english/advisories/2009/1818https://exchange.xforce.ibmcloud.com/vulnerabilities/45791https://issues.apache.org/bugzilla/show_bug.cgi?id=25835https://lists.apache.org/thread.html/29dc6c2b625789e70a9c4756b5a327e6547273ff8bde7e0327af48c5%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/c62b0e3a7bf23342352a5810c640a94b6db69957c5c19db507004d74%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/rb71997f506c6cc8b530dd845c084995a9878098846c7b4eacfae8db3%40%3Cdev.tomcat.apache.org%3E
2008-10-13
Published