Project

General

Profile

Actions

Bug #36760

closed

CVE-2023-4886: World readable tomcat server.xml contains passwords

Added by Ewoud Kohl van Wijngaarden about 1 year ago. Updated about 1 year ago.


Description

The file /etc/tomcat/server.xml contains passwords and is world readable. The actual keystore is limited by file permissions, but server.xml should also be limited.


Files

Actions

Also available in: Atom PDF