Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41080

Опубликовано: 28 авг. 2023
Источник: redhat
CVSS3: 6.1
EPSS Средний

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

A flaw was found in Apache Tomcat if the default web application is configured with FormAuthenticator. This issue allows a specially crafted URL to trigger a redirect to an arbitrary URL.

Отчет

The pki-servlet-engine package has been obsoleted by the Tomcat package. Therefore, this issue will be fixed in the Tomcat package rather than the pki-serlvet-engine package. Please follow the RHEL Tomcat trackers instead for the updates. Red Hat Satellite is not directly impacted by this issue, since it does not embed the dependency on their offer deliveries. However, end users of Red Hat Satellite are using Tomcat via RHEL channels, which provides Tomcat dependency needed by candlepin to function in Satellite.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2tomcatNot affected
Red Hat build of Apache Camel for Spring Boot 3tomcatNot affected
Red Hat build of OptaPlanner 8tomcatWill not fix
Red Hat Data Grid 8tomcatNot affected
Red Hat Decision Manager 7tomcatWill not fix
Red Hat Enterprise Linux 7tomcatOut of support scope
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 8pki-servlet-containerWill not fix
Red Hat Enterprise Linux 9pki-servlet-engineWill not fix
Red Hat Fuse 7tomcatWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2235370tomcat: Open Redirect vulnerability in FORM authentication

EPSS

Процентиль: 93%
0.11116
Средний

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
nvd
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application.

CVSS3: 6.1
debian
почти 2 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in F ...

suse-cvrf
больше 1 года назад

Security update for tomcat

CVSS3: 6.1
github
почти 2 года назад

Apache Tomcat Open Redirect vulnerability

EPSS

Процентиль: 93%
0.11116
Средний

6.1 Medium

CVSS3