Lucene search

K
tomcatApache TomcatTOMCAT:AEEBC23F2ADE82A4EDD7A346011A3105
HistoryAug 25, 2023 - 12:00 a.m.

Fixed in Apache Tomcat 8.5.93

2023-08-2500:00:00
Apache Tomcat
tomcat.apache.org
142
apache tomcat
open redirect
cve-2023-41080
web application
form authentication
security
vulnerability
software
commit 4998ad74

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.007

Percentile

81.0%

Moderate: Open redirect CVE-2023-41080

If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.

This was fixed with commit 4998ad74.

This issue was reported to the Tomcat Security Team on 17 August 2023. The issue was made public on 22 August 2023.

Affects: 8.5.0 to 8.5.92

Affected configurations

Vulners
Node
apachetomcatRange8.5.0
OR
apachetomcatRange8.5.92
VendorProductVersionCPE
apachetomcat*cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.007

Percentile

81.0%