[Bug 70141] Shell Command Injection via CGIServlet Argument Injection on Linux
[email protected] Thu, 09 Jul 2026 13:29:15 +0000
| Newsgroups | gmane.comp.jakarta.tomcat.devel |
|---|---|
| Message-ID | <[email protected]/bugzilla/> |
https://bz.apache.org/bugzilla/show_bug.cgi?id=70141 Christopher Schultz <[email protected]> changed: What |Removed |Added ---------------------------------------------------------------------------- OS| |All Resolution|--- |INVALID Status|NEW |RESOLVED --- Comment #1 from Christopher Schultz <[email protected]> --- This is security vulnerability in the script and not in the CGIServlet itself. The only reason there is some protection on Windows is due to the fact that that there are multiple incompatible parsing regimes in Windows environments which makes protection difficult, while no such difficulties exist on UNIX-like environments. -- You are receiving this mail because: You are the assignee for the bug.