Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-80565
HistoryAug 29, 2023 - 12:00 a.m.

Apache Tomcat Open Redirect Vulnerability (CNVD-2023-80565)

2023-08-2900:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
apache tomcat
open redirection vulnerability
form authentication
servlet
javaserver page
untrusted sites

6.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.6%

Apache Tomcat is the United States Apache (Apache) Foundation of a lightweight Web application server. The program implements the Servlet and JavaServer Page (JSP) support. An open redirection vulnerability exists in Apache Tomcat, which stems from the FORM authentication feature not handling target jumps appropriately, and can be exploited by an attacker to redirect URLs to untrusted sites.