Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-41080

Опубликовано: 25 авг. 2023
Источник: debian

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat10fixed10.1.13-1package
tomcat9fixed9.0.70-2package
tomcat8removedpackage

Примечания

  • https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f

  • https://github.com/apache/tomcat/commit/bb4624a9f3e69d495182ebfa68d7983076407a27 (10.1.13)

  • https://github.com/apache/tomcat/commit/77c0ce2d169efa248b64b992e547aad549ec906b (9.0.80)

  • Starting with 9.0.70-2 Tomcat9 no longer ships the server stack, using that as the fixed version

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
redhat
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
nvd
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

suse-cvrf
больше 1 года назад

Security update for tomcat

CVSS3: 6.1
github
почти 2 года назад

Apache Tomcat Open Redirect vulnerability