5.3

CVE-2023-45648

Apache Tomcat: Trailer header parsing too lenient

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially 
crafted, invalid trailer header could cause Tomcat to treat a single 
request as multiple requests leading to the possibility of request 
smuggling when behind a reverse proxy.

Older, EOL versions may also be affected.


Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 8.5.0 < 8.5.94
Apache ≫ Tomcat Version >= 9.0.1 < 9.0.81
Apache ≫ Tomcat Version >= 10.1.1 < 10.1.14
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone10
Apache ≫ Tomcat Version 9.0.0 Update milestone11
Apache ≫ Tomcat Version 9.0.0 Update milestone12
Apache ≫ Tomcat Version 9.0.0 Update milestone13
Apache ≫ Tomcat Version 9.0.0 Update milestone14
Apache ≫ Tomcat Version 9.0.0 Update milestone15
Apache ≫ Tomcat Version 9.0.0 Update milestone16
Apache ≫ Tomcat Version 9.0.0 Update milestone17
Apache ≫ Tomcat Version 9.0.0 Update milestone18
Apache ≫ Tomcat Version 9.0.0 Update milestone19
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone20
Apache ≫ Tomcat Version 9.0.0 Update milestone21
Apache ≫ Tomcat Version 9.0.0 Update milestone22
Apache ≫ Tomcat Version 9.0.0 Update milestone23
Apache ≫ Tomcat Version 9.0.0 Update milestone24
Apache ≫ Tomcat Version 9.0.0 Update milestone25
Apache ≫ Tomcat Version 9.0.0 Update milestone26
Apache ≫ Tomcat Version 9.0.0 Update milestone27
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Apache ≫ Tomcat Version 10.1.0 Update milestone1
Apache ≫ Tomcat Version 10.1.0 Update milestone10
Apache ≫ Tomcat Version 10.1.0 Update milestone11
Apache ≫ Tomcat Version 10.1.0 Update milestone12
Apache ≫ Tomcat Version 10.1.0 Update milestone13
Apache ≫ Tomcat Version 10.1.0 Update milestone14
Apache ≫ Tomcat Version 10.1.0 Update milestone15
Apache ≫ Tomcat Version 10.1.0 Update milestone16
Apache ≫ Tomcat Version 10.1.0 Update milestone17
Apache ≫ Tomcat Version 10.1.0 Update milestone18
Apache ≫ Tomcat Version 10.1.0 Update milestone19
Apache ≫ Tomcat Version 10.1.0 Update milestone2
Apache ≫ Tomcat Version 10.1.0 Update milestone20
Apache ≫ Tomcat Version 10.1.0 Update milestone3
Apache ≫ Tomcat Version 10.1.0 Update milestone4
Apache ≫ Tomcat Version 10.1.0 Update milestone5
Apache ≫ Tomcat Version 10.1.0 Update milestone6
Apache ≫ Tomcat Version 10.1.0 Update milestone7
Apache ≫ Tomcat Version 10.1.0 Update milestone8
Apache ≫ Tomcat Version 10.1.0 Update milestone9
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Debian ≫ Debian Linux Version 12.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.85% 0.922
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA-ADP 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2023/dsa-5522
Third Party Advisory
https://www.debian.org/security/2023/dsa-5521
Third Party Advisory
https://security.netapp.com/advisory/ntap-20231103-0007/
http://www.openwall.com/lists/oss-security/2023/10/10/10
Third Party Advisory
Mailing List
https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp
Vendor Advisory