Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34487

Опубликовано: 09 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

A flaw was found in Apache Tomcat. The cloud membership for clustering component was vulnerable to the insertion of sensitive information into log files. This vulnerability could lead to the exposure of the Kubernetes bearer token, which is a credential used for authentication within a Kubernetes cluster, potentially allowing unauthorized access to cluster resources.

Отчет

Low impact. This vulnerability in Apache Tomcat affects the cloud membership for clustering component, potentially exposing Kubernetes bearer tokens in log files. Exploitation requires the cloud membership feature to be enabled and an attacker to have access to the system's log files. Red Hat Enterprise Linux versions are affected if running Apache Tomcat with this specific clustering configuration.

Меры по смягчению последствий

Disable the cloud membership for clustering feature in Apache Tomcat if it is not actively used. Additionally, ensure that access to Apache Tomcat log files is strictly controlled and limited to authorized personnel only to prevent unauthorized disclosure of sensitive information. If the cloud membership for clustering feature is disabled, a restart of the Apache Tomcat service may be required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatFix deferred
Red Hat Enterprise Linux 10tomcat9Fix deferred
Red Hat Enterprise Linux 6tomcat6Out of support scope
Red Hat Enterprise Linux 7tomcatFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineFix deferred
Red Hat Enterprise Linux 8tomcatFix deferred
Red Hat Enterprise Linux 9pki-servlet-engineFix deferred
Red Hat Enterprise Linux 9tomcatFix deferred
Red Hat JBoss Web Server 5tomcatUnder investigation
Red Hat JBoss Web Server 6.2.3tomcatFixedRHSA-2026:2040626.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-538
https://bugzilla.redhat.com/show_bug.cgi?id=2457038Apache Tomcat: Apache Tomcat: Information disclosure via sensitive data in log files

EPSS

Процентиль: 36%
0.00447
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
nvd
4 месяца назад

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
debian
4 месяца назад

Insertion of Sensitive Information into Log File vulnerability in the ...

CVSS3: 7.5
github
4 месяца назад

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00447
Низкий

6.5 Medium

CVSS3