Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34500

Опубликовано: 09 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 6.5

Описание

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

РелизСтатусПримечание
devel

not-affected

10.1.54
esm-apps/noble

not-affected

code not present
esm-apps/resolute

needed

jammy

DNE

noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

upstream

released

10.1.54

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.21
esm-apps/resolute

needed

jammy

DNE

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

upstream

released

11.0.21

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.117
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

needed

jammy

not-affected

code not present
noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

Показывать по

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
5 месяцев назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
nvd
5 месяцев назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
debian
5 месяцев назад

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 6.5
redos
4 месяца назад

Уязвимость tomcat11

CVSS3: 6.5
redos
4 месяца назад

Уязвимость tomcat10

6.5 Medium

CVSS3