Lucene search

K
nvd[email protected]NVD:CVE-2023-41080
HistoryAug 25, 2023 - 9:15 p.m.

CVE-2023-41080

2023-08-2521:15:09
CWE-601
web.nvd.nist.gov
3
cve-2023-41080
untrusted site
open redirect
form authentication
apache tomcat
version 11.0.0-m1 to 11.0.0-m10
version 10.1.0-m1 to 10.0.12
version 9.0.0-m1 to 9.0.79
version 8.5.0 to 8.5.92
root web application

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.6%

URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.

The vulnerability is limited to the ROOT (default) web application.

Affected configurations

NVD
Node
apachetomcatRange8.5.08.5.92
OR
apachetomcatRange9.0.09.0.79
OR
apachetomcatRange10.1.010.1.12
OR
apachetomcatMatch11.0.0milestone1
OR
apachetomcatMatch11.0.0milestone10
OR
apachetomcatMatch11.0.0milestone2
OR
apachetomcatMatch11.0.0milestone3
OR
apachetomcatMatch11.0.0milestone4
OR
apachetomcatMatch11.0.0milestone5
OR
apachetomcatMatch11.0.0milestone6
OR
apachetomcatMatch11.0.0milestone7
OR
apachetomcatMatch11.0.0milestone8
OR
apachetomcatMatch11.0.0milestone9
Node
debiandebian_linuxMatch10.0
OR
debiandebian_linuxMatch11.0

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.6%