← Back to CVE List

CVE-2019-0221

Published: 2019-05-28T22:29Z
Last Modified: 2024-11-21T04:16Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt