Apache Tomcat 7.0.11 Security Constraint Bypass

0
63

A regression in the Apache Tomcat version 7.0.11 fix for CVE-2011-1088 meant that security constraints were ignored when no login configuration was present in the web.xml and the web application was marked as meta-data complete.

Source: Apache Tomcat 7.0.11 Security Constraint Bypass