First published: Fri Aug 25 2023(Updated: )
Apache Tomcat could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the FORM authentication feature. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Tomcat | >=8.5.0<=8.5.92 | |
Apache Tomcat | >=9.0.0<=9.0.79 | |
Apache Tomcat | >=10.1.0<=10.1.12 | |
Apache Tomcat | =11.0.0-milestone1 | |
Apache Tomcat | =11.0.0-milestone10 | |
Apache Tomcat | =11.0.0-milestone2 | |
Apache Tomcat | =11.0.0-milestone3 | |
Apache Tomcat | =11.0.0-milestone4 | |
Apache Tomcat | =11.0.0-milestone5 | |
Apache Tomcat | =11.0.0-milestone6 | |
Apache Tomcat | =11.0.0-milestone7 | |
Apache Tomcat | =11.0.0-milestone8 | |
Apache Tomcat | =11.0.0-milestone9 | |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=11.0.0-M1<11.0.0-M11 | 11.0.0-M11 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=10.1.0-M1<10.1.13 | 10.1.13 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=9.0.0-M1<9.0.80 | 9.0.80 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.5.0<8.5.93 | 8.5.93 |
maven/org.apache.tomcat:tomcat | >=8.5.0<8.5.93 | 8.5.93 |
maven/org.apache.tomcat:tomcat | >=9.0.0-M1<9.0.80 | 9.0.80 |
maven/org.apache.tomcat:tomcat | >=10.1.0-M1<10.1.13 | 10.1.13 |
maven/org.apache.tomcat:tomcat | >=11.0.0-M1<11.0.0-M11 | 11.0.0-M11 |
debian/tomcat10 | 10.1.6-1+deb12u1 10.1.16-1 | |
debian/tomcat9 | <=9.0.31-1~deb10u6<=9.0.43-2~deb11u6 | 9.0.31-1~deb10u10 9.0.43-2~deb11u9 9.0.70-2 |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
redhat/tomcat | <11.0.0 | 11.0.0 |
redhat/tomcat | <10.1.13 | 10.1.13 |
redhat/tomcat | <9.0.80 | 9.0.80 |
redhat/tomcat | <8.5.93 | 8.5.93 |
IBM IBM® Engineering Requirements Management DOORS | <=9.7.2.7 | |
IBM IBM® Engineering Requirements Management DOORS Web Access | <=9.7.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41080.
The severity of CVE-2023-41080 is medium with a severity value of 6.1.
CVE-2023-41080 allows for URL redirection to untrusted sites, posing a risk to the security of Apache Tomcat.
CVE-2023-41080 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79, and from 8.5.0 through 8.5.92.
To fix CVE-2023-41080, upgrade Apache Tomcat to versions 8.5.93, 9.0.80, 10.1.13, or 11.0.0-M11, depending on the affected version.