important · Edge devices
Template syntax in a request path can bypass Tomcat security constraints on WebSocket endpoints.
Affects
Apache Tomcat, a cross-platform Java Servlet and WebSocket application server.
A network client can make Tomcat interpret an attacker-supplied candidate path as an endpoint template and reach a protected WebSocket endpoint without the configured authentication constraint. Apache has published the correction.