[GHSA-cw54-59pw-4g8c] Apache Tomcat Improper Access Control vulnerability #4376
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Update
Affected package names
Comments
From the NVD website reference https://svn.apache.org/viewvc?view=revision&revision=1767676, the affected file is org/apache/catalina/mbeans/JmxRemoteLifecycleListener.java. By downloading and unpacking the source code from
https://repo1.maven.org/maven2/org/apache/tomcat/tomcat-catalina/7.0.73/https://repo1.maven.org/maven2/org/apache/tomcat/tomcat-catalina/7.0.73/tomcat-catalina-7.0.73-sources.jar
and
https://repo1.maven.org/maven2/org/apache/tomcat/tomcat-catalina/7.0.73/https://repo1.maven.org/maven2/org/apache/tomcat/tomcat-catalina-jmx-remote/7.0.73/tomcat-catalina-jmx-remote-7.0.73-sources.jar
It looks like org/apache/catalina/mbeans/JmxRemoteLifecycleListener.java is inside of tomcat-catalina-jmx-remote not tomcat-catalina. Therefore I think the affected package should also include tomcat-catalina-jmx-remote.
Related to #4278