An open index of dependabot pull requests across open source projects.

Apache Tomcat OS Command Injection vulnerability

GHSA-8vmx-qmch-mpqg CVE-2019-0232
Description:

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
maven org.apache.tomcat.embed:tomcat-embed-core >= 9.0.0.M1, < 9.0.17
>= 7.0.0, < 7.0.94
>= 8.0.0, < 8.5.40
9.0.17
Related Dependabot Pull Requests
Advisory Details
Published: April 18, 2019 over 7 years ago
Updated: July 23, 2026 1 day ago
CVSS Score: 8.1 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 99.65% 100th percentile
Source: Github
Classification: GENERAL
UUID: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTh2bXgtcW1jaC1tcHFn
References