6.1

CVE-2023-41080

Apache Tomcat: Open redirect with FORM authentication

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
Older, EOL versions may also be affected.


The vulnerability is limited to the ROOT (default) web application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 8.5.0 <= 8.5.92
Apache ≫ Tomcat Version >= 9.0.0 <= 9.0.79
Apache ≫ Tomcat Version >= 10.1.0 <= 10.1.12
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.97% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5522
Third Party Advisory
https://www.debian.org/security/2023/dsa-5521
Third Party Advisory
https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f
Patch
Vendor Advisory
Issue Tracking
https://security.netapp.com/advisory/ntap-20230921-0006/
Third Party Advisory