Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34500

Опубликовано: 09 апр. 2026
Источник: debian
EPSS Низкий

Описание

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat11fixed11.0.21-1package
tomcat10fixed10.1.54-1package
tomcat9fixed9.0.70-2package

Примечания

  • Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version

  • Fixed by: https://github.com/apache/tomcat/commit/c13e60e732ea6d07087293a41ad1866c20848271 (11.0.21)

  • Fixed by: https://github.com/apache/tomcat/commit/29b56a56ce9e7d044b6162a99af0f38529b3a208 (10.1.54)

  • Fixed by: https://github.com/apache/tomcat/commit/ff589ab26e8250a2ca4286d986305318c033ff9f (9.0.117)

  • https://www.openwall.com/lists/oss-security/2026/04/09/29

EPSS

Процентиль: 38%
0.00469
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 5.9
redhat
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
nvd
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
github
4 месяца назад

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная c недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 38%
0.00469
Низкий