Логотип exploitDog
bind:"BDU:2025-10838" OR bind:"CVE-2023-28708"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-10838" OR bind:"CVE-2023-28708"

Количество 12

Количество 12

fstec логотип

BDU:2025-10838

около 3 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20250828-03

7 месяцев назад

Уязвимость tomcat

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-28708

около 3 лет назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2023-28708

около 3 лет назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-28708

около 3 лет назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-28708

около 3 лет назад

When using the RemoteIpFilter with requests received from a reverse ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1672-1

около 3 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1669-1

около 3 лет назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-2c9m-w27f-53rm

около 3 лет назад

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1769-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
oracle-oval логотип

ELSA-2023-7065

больше 2 лет назад

ELSA-2023-7065: tomcat security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6570

больше 2 лет назад

ELSA-2023-6570: tomcat security and bug fix update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-10838

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4.3
0%
Низкий
около 3 лет назад
redos логотип
ROS-20250828-03

Уязвимость tomcat

CVSS3: 4.3
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1672-1

Security update for tomcat

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1669-1

Security update for tomcat

0%
Низкий
около 3 лет назад
github логотип
GHSA-2c9m-w27f-53rm

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:1769-1

Security update for tomcat

почти 3 года назад
oracle-oval логотип
ELSA-2023-7065

ELSA-2023-7065: tomcat security and bug fix update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-6570

ELSA-2023-6570: tomcat security and bug fix update (MODERATE)

больше 2 лет назад

Уязвимостей на страницу