Логотип exploitDog
bind:"CVE-2023-28708" OR bind:"CVE-2023-24998" OR bind:"CVE-2023-28709"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-28708" OR bind:"CVE-2023-24998" OR bind:"CVE-2023-28709"

Количество 35

Количество 35

oracle-oval логотип

ELSA-2023-7065

около 2 лет назад

ELSA-2023-7065: tomcat security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-6570

около 2 лет назад

ELSA-2023-6570: tomcat security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1769-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2505-1

больше 2 лет назад

Security update for tomcat

EPSS: Низкий
ubuntu логотип

CVE-2023-28708

почти 3 года назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2023-28708

почти 3 года назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-28708

почти 3 года назад

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-28708

почти 3 года назад

When using the RemoteIpFilter with requests received from a reverse ...

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1672-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:1669-1

почти 3 года назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-2c9m-w27f-53rm

почти 3 года назад

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2025-10838

почти 3 года назад

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4.3
EPSS: Низкий
redos логотип

ROS-20250828-03

5 месяцев назад

Уязвимость tomcat

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-28709

больше 2 лет назад

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-28709

больше 2 лет назад

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-28709

больше 2 лет назад

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-28709

больше 2 лет назад

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-24998

почти 3 года назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2023-24998

почти 3 года назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2023-24998

почти 3 года назад

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2023-7065

ELSA-2023-7065: tomcat security and bug fix update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2023-6570

ELSA-2023-6570: tomcat security and bug fix update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:1769-1

Security update for tomcat

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2505-1

Security update for tomcat

больше 2 лет назад
ubuntu логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

CVSS3: 4.3
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-28708

When using the RemoteIpFilter with requests received from a reverse ...

CVSS3: 4.3
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1672-1

Security update for tomcat

0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:1669-1

Security update for tomcat

0%
Низкий
почти 3 года назад
github логотип
GHSA-2c9m-w27f-53rm

Apache Tomcat vulnerable to Unprotected Transport of Credentials

CVSS3: 4.3
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2025-10838

Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием флага «Secure» в файлах cookie сеанса, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4.3
0%
Низкий
почти 3 года назад
redos логотип
ROS-20250828-03

Уязвимость tomcat

CVSS3: 4.3
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2023-28709

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-28709

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28709

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28709

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-24998

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
48%
Средний
почти 3 года назад
redhat логотип
CVE-2023-24998

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 6.5
48%
Средний
почти 3 года назад
nvd логотип
CVE-2023-24998

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.

CVSS3: 7.5
48%
Средний
почти 3 года назад

Уязвимостей на страницу