Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34500

Опубликовано: 09 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.5

Описание

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

РелизСтатусПримечание
devel

not-affected

10.1.54
esm-apps/noble

not-affected

code not present
esm-apps/resolute

needed

jammy

DNE

noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

upstream

released

10.1.54

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.21
esm-apps/resolute

needed

jammy

DNE

noble

DNE

questing

ignored

end of life, was needed
resolute

needed

upstream

released

11.0.21

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.117
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

needed

jammy

not-affected

code not present
noble

not-affected

code not present
questing

ignored

end of life, was needed
resolute

needed

Показывать по

EPSS

Процентиль: 38%
0.00469
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
redhat
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
nvd
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

CVSS3: 6.5
debian
4 месяца назад

CLIENT_CERT authentication does not fail as expected for some scenario ...

CVSS3: 6.5
github
4 месяца назад

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная c недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 38%
0.00469
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-34500