Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-46589
HistoryNov 28, 2023 - 12:00 a.m.

CVE-2023-46589

2023-11-2800:00:00
ubuntu.com
ubuntu.com
63
apache tomcat
input validation
http headers

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.005

Percentile

76.1%

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from
11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1
through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP
trailer headers. A trailer header that exceeded the header size limit could
cause Tomcat to treat a single request as multiple requests leading to the
possibility of request smuggling when behind a reverse proxy. Users are
recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards,
9.0.83 onwards or 8.5.96 onwards, which fix the issue.

Bugs

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

7.4

Confidence

High

EPSS

0.005

Percentile

76.1%