|
1 | 1 | { |
2 | 2 | "schema_version": "1.4.0", |
3 | 3 | "id": "GHSA-563x-q5rq-57qp", |
4 | | - "modified": "2026-04-10T22:07:01Z", |
| 4 | + "modified": "2026-04-15T22:39:21Z", |
5 | 5 | "published": "2026-04-09T21:31:29Z", |
6 | 6 | "aliases": [ |
7 | 7 | "CVE-2026-24880" |
|
18 | 18 | { |
19 | 19 | "package": { |
20 | 20 | "ecosystem": "Maven", |
21 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 21 | + "name": "org.apache.tomcat:tomcat-tribes" |
22 | 22 | }, |
23 | 23 | "ranges": [ |
24 | 24 | { |
|
37 | 37 | { |
38 | 38 | "package": { |
39 | 39 | "ecosystem": "Maven", |
40 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 40 | + "name": "org.apache.tomcat:tomcat-tribes" |
41 | 41 | }, |
42 | 42 | "ranges": [ |
43 | 43 | { |
|
56 | 56 | { |
57 | 57 | "package": { |
58 | 58 | "ecosystem": "Maven", |
59 | | - "name": "org.apache.tomcat:tomcat-catalina" |
| 59 | + "name": "org.apache.tomcat:tomcat-tribes" |
60 | 60 | }, |
61 | 61 | "ranges": [ |
62 | 62 | { |
|
70 | 70 | } |
71 | 71 | ] |
72 | 72 | } |
73 | | - ] |
| 73 | + ], |
| 74 | + "database_specific": { |
| 75 | + "last_known_affected_version_range": "<= 11.0.18" |
| 76 | + } |
74 | 77 | }, |
75 | 78 | { |
76 | 79 | "package": { |
|
127 | 130 | } |
128 | 131 | ] |
129 | 132 | } |
130 | | - ] |
| 133 | + ], |
| 134 | + "database_specific": { |
| 135 | + "last_known_affected_version_range": "<= 11.0.18" |
| 136 | + } |
| 137 | + } |
| 138 | + ], |
| 139 | + "references": [ |
| 140 | + { |
| 141 | + "type": "ADVISORY", |
| 142 | + "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24880" |
131 | 143 | }, |
132 | 144 | { |
133 | | - "package": { |
134 | | - "ecosystem": "Maven", |
135 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
136 | | - }, |
137 | | - "ranges": [ |
138 | | - { |
139 | | - "type": "ECOSYSTEM", |
140 | | - "events": [ |
141 | | - { |
142 | | - "introduced": "7.0.0" |
143 | | - }, |
144 | | - { |
145 | | - "fixed": "9.0.116" |
146 | | - } |
147 | | - ] |
148 | | - } |
149 | | - ] |
| 145 | + "type": "WEB", |
| 146 | + "url": "https://github.com/apache/tomcat/commit/1b586d6aa8ae65726da5fa8799427b5d4718478a" |
150 | 147 | }, |
151 | 148 | { |
152 | | - "package": { |
153 | | - "ecosystem": "Maven", |
154 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
155 | | - }, |
156 | | - "ranges": [ |
157 | | - { |
158 | | - "type": "ECOSYSTEM", |
159 | | - "events": [ |
160 | | - { |
161 | | - "introduced": "10.1.0-M1" |
162 | | - }, |
163 | | - { |
164 | | - "fixed": "10.1.52" |
165 | | - } |
166 | | - ] |
167 | | - } |
168 | | - ] |
| 149 | + "type": "WEB", |
| 150 | + "url": "https://github.com/apache/tomcat/commit/1e71441a15972f56e661b0b549fb9e5d838b83bb" |
169 | 151 | }, |
170 | 152 | { |
171 | | - "package": { |
172 | | - "ecosystem": "Maven", |
173 | | - "name": "org.apache.tomcat.embed:tomcat-embed-core" |
174 | | - }, |
175 | | - "ranges": [ |
176 | | - { |
177 | | - "type": "ECOSYSTEM", |
178 | | - "events": [ |
179 | | - { |
180 | | - "introduced": "11.0.0-M1" |
181 | | - }, |
182 | | - { |
183 | | - "fixed": "11.0.20" |
184 | | - } |
185 | | - ] |
186 | | - } |
187 | | - ] |
188 | | - } |
189 | | - ], |
190 | | - "references": [ |
| 153 | + "type": "WEB", |
| 154 | + "url": "https://github.com/apache/tomcat/commit/2cb06c34f661ca42f7570bbcc21e99806184bcc5" |
| 155 | + }, |
191 | 156 | { |
192 | | - "type": "ADVISORY", |
193 | | - "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-24880" |
| 157 | + "type": "WEB", |
| 158 | + "url": "https://github.com/apache/tomcat/commit/6d478dbe18b7c4bb671c30fedf130309b0dab77c" |
| 159 | + }, |
| 160 | + { |
| 161 | + "type": "WEB", |
| 162 | + "url": "https://github.com/apache/tomcat/commit/f07df938d00f7419b40fa65aa912966d0efac522" |
| 163 | + }, |
| 164 | + { |
| 165 | + "type": "WEB", |
| 166 | + "url": "https://github.com/apache/tomcat/commit/fde1a8235fb73125217bd41e162aa0a113f33552" |
194 | 167 | }, |
195 | 168 | { |
196 | 169 | "type": "PACKAGE", |
|
200 | 173 | "type": "WEB", |
201 | 174 | "url": "https://lists.apache.org/thread/2c682qnlg2tv4o5knlggqbl9yc2gb5sn" |
202 | 175 | }, |
| 176 | + { |
| 177 | + "type": "WEB", |
| 178 | + "url": "https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53" |
| 179 | + }, |
| 180 | + { |
| 181 | + "type": "WEB", |
| 182 | + "url": "https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20" |
| 183 | + }, |
| 184 | + { |
| 185 | + "type": "WEB", |
| 186 | + "url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116" |
| 187 | + }, |
| 188 | + { |
| 189 | + "type": "WEB", |
| 190 | + "url": "https://www.herodevs.com/vulnerability-directory/cve-2026-24880" |
| 191 | + }, |
203 | 192 | { |
204 | 193 | "type": "WEB", |
205 | 194 | "url": "http://www.openwall.com/lists/oss-security/2026/04/09/20" |
|
0 commit comments