Описание
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
A flaw was found in Apache Tomcat. This vulnerability, an authentication bypass by capture-replay, affects the DIGEST authenticator. A remote attacker can exploit this by making a specially crafted DIGEST authenticated request with a nonceCount at the upper boundary of the replay window. This allows the attacker to replay the request once, potentially bypassing authentication.
Отчет
This Moderate impact flaw in Apache Tomcat's DIGEST authenticator allows a limited authentication bypass through a replay attack. While the attack complexity is high, a remote attacker could potentially replay a single authenticated request if the nonceCount is at the upper boundary of the replay window, leading to limited unauthorized access. This vulnerability affects configurations utilizing DIGEST authentication.
Меры по смягчению последствий
To mitigate this issue, disable DIGEST authentication in Apache Tomcat if it is not a required authentication mechanism for your deployment. Refer to the Apache Tomcat documentation for guidance on configuring authentication methods. Disabling DIGEST authentication will affect services that depend on it. A restart of the Tomcat service is necessary for the configuration changes to be applied.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 10 | tomcat9 | Under investigation | ||
| Red Hat Enterprise Linux 6 | tomcat6 | Under investigation | ||
| Red Hat Enterprise Linux 7 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/pki-servlet-engine | Under investigation | ||
| Red Hat Enterprise Linux 8 | tomcat | Under investigation | ||
| Red Hat Enterprise Linux 9 | tomcat | Under investigation | ||
| Red Hat JBoss Web Server 5 | tomcat | Out of support scope | ||
| Red Hat JBoss Web Server 6 | tomcat | Affected | ||
| Red Hat JBoss Web Server 7 | tomcat | Affected |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat ...
4.8 Medium
CVSS3