Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv25-8xcx-gqjc

Опубликовано: 12 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Apache Tomcat - WebSocket authentication header exposure

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.2 to 9.0.117 Older, unsupported versions may also be affected

Description: If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host.

Mitigation: Users of the affected versions should apply one of the following mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit: This issue was identified by lokerxx

Пакеты

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

< 9.0.118

9.0.118

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.55

10.1.55

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.22

11.0.22

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

< 9.0.118

9.0.118

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.55

10.1.55

Наименование

org.apache.tomcat:tomcat

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.22

11.0.22

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

< 9.0.118

9.0.118

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 10.1.0-M1, < 10.1.55

10.1.55

Наименование

org.apache.tomcat:tomcat-catalina

maven
Затронутые версииВерсия исправления

>= 11.0.0-M1, < 11.0.22

11.0.22

EPSS

Процентиль: 45%
0.006
Низкий

7.3 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.3
ubuntu
3 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

CVSS3: 6.5
redhat
3 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

CVSS3: 7.3
nvd
3 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

CVSS3: 7.3
debian
3 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebS ...

CVSS3: 7.3
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 45%
0.006
Низкий

7.3 High

CVSS3

Дефекты

CWE-200