Lucene search

K
githubGitHub Advisory DatabaseGHSA-R6J3-PX5G-CQ3X
HistoryOct 10, 2023 - 9:31 p.m.

Apache Tomcat Improper Input Validation vulnerability

2023-10-1021:31:12
CWE-20
GitHub Advisory Database
github.com
24
apache tomcat
input validation
vulnerability
http trailer headers
request smuggling
upgrade

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.002 Low

EPSS

Percentile

60.6%

Improper Input Validation vulnerability in Apache Tomcat.

Tomcatย from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.

Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.

Affected configurations

Vulners
Node
youtube_embed_projectyoutube_embedRange<8.5.94
OR
embed_pdf_projectembed_pdfRange<9.0.81
OR
embed_pdf_projectembed_pdfRange<10.1.14
OR
embed_pdf_projectembed_pdfRange<11.0.0-M12
OR
org.apache.tomcat\Matchtomcat
OR
org.apache.tomcat\Matchtomcat
OR
org.apache.tomcat\Matchtomcat
OR
org.apache.tomcat\Matchtomcat

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

0.002 Low

EPSS

Percentile

60.6%