Re: [SECURITY] CVE-2020-9484 Apache Tomcat Remote Code Execution via session persistence

2020-05-24 Thread Mark Thomas
On May 24, 2020 4:49:50 PM UTC, Stefan Mayr wrote: >Hi, > >Am 20.05.2020 um 17:19 schrieb Mark Thomas: >> CVE-2020-9484 Apache Tomcat Remote Code Execution via session >persistence >> >> Severity: High >> >> Vendor: The Apache Software Foundation >> >> Versions Affected: >> Apache Tomcat 10.0.0

Re: [SECURITY] CVE-2020-9484 Apache Tomcat Remote Code Execution via session persistence

2020-05-24 Thread Stefan Mayr
Hi, Am 20.05.2020 um 17:19 schrieb Mark Thomas: > CVE-2020-9484 Apache Tomcat Remote Code Execution via session persistence > > Severity: High > > Vendor: The Apache Software Foundation > > Versions Affected: > Apache Tomcat 10.0.0-M1 to 10.0.0-M4 > Apache Tomcat 9.0.0.M1 to 9.0.34 > Apache Tom

Re: [SECURITY] CVE-2020-9484 Apache Tomcat Remote Code Execution via session persistence

2020-05-21 Thread emma davis
Hi, When I run  dns leaktest  https://www.dnsleaktest.com/I have a setup  which shows 32 Servers identifying my origin.All from  different continents If some one  did  pen test or ethical hacking with same setup as myself using these tools for bug bounties on Tomcat. How what is the defence agai