Lucene search

K
tomcatApache TomcatTOMCAT:53B6E349F00FD73D8D197D64C7C51EF9
HistoryAug 25, 2023 - 12:00 a.m.

Fixed in Apache Tomcat 10.1.13

2023-08-2500:00:00
Apache Tomcat
tomcat.apache.org
74
apache tomcat
security
open redirect
cve-2023-41080
form authentication

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.007

Percentile

81.0%

Moderate: Open redirect CVE-2023-41080

If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.

This was fixed with commit bb4624a9.

This issue was reported to the Tomcat Security Team on 17 August 2023. The issue was made public on 22 August 2023.

Affects: 10.1.0-M1 to 10.1.12

Affected configurations

Vulners
Node
apachetomcatRange10.1.0-M1
OR
apachetomcatRange10.1.12
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.007

Percentile

81.0%