Логотип exploitDog
bind:"GHSA-fpj8-gq4v-p354" OR bind:"CVE-2025-66614"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-fpj8-gq4v-p354" OR bind:"CVE-2025-66614"

Количество 8

Количество 8

github логотип

GHSA-fpj8-gq4v-p354

около 1 месяца назад

Apache Tomcat - Client certificate verification bypass

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2025-66614

около 1 месяца назад

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web applicati...

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2025-66614

около 1 месяца назад

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-66614

около 1 месяца назад

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the we

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2025-66614

около 1 месяца назад

Improper Input Validation vulnerability. This issue affects Apache To ...

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20350-1

13 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0890-1

13 дней назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0877-1

14 дней назад

Security update for tomcat11

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fpj8-gq4v-p354

Apache Tomcat - Client certificate verification bypass

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web applicati...

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the we

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache To ...

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20350-1

Security update for tomcat

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0890-1

Security update for tomcat10

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0877-1

Security update for tomcat11

14 дней назад

Уязвимостей на страницу