Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39930
HistoryMar 24, 2023 - 1:12 a.m.

Information Disclosure

2023-03-2401:12:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18
information disclosure
tomcat
catalina
remoteipfilter
x-forwarded-proto
session cookie

EPSS

0.001

Percentile

40.4%

org.apache.tomcat:tomcat-catalina is vulnerable to Information Disclosure. The vulnerability is due to the setSecure function in RemoteIpFilter.java because http requests with the X-Forwarded-Proto header set to https do not include the secure attribute, which could result in an session cookie being transmitted over an insecure channel.