REDHAT-BUG-2326972: Low severity Apache Tomcat vulnerability

Published Nov 18, 2024
·
Updated

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.

Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.

Affected Software

1 affected component
Apache Tomcat>=11.0.0-M1<=11.0.0-M26, >=10.1.0-M1<=10.1.30, >=9.0.0-M1<=9.0.95

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade apache/tomcat to a version that resolves this vulnerability.

    Fixed in 11.0.0
  2. Upgrade

    Upgrade apache/tomcat to a version that resolves this vulnerability.

    Fixed in 10.1.31
  3. Upgrade

    Upgrade apache/tomcat to a version that resolves this vulnerability.

    Fixed in 9.0.96

Event History

Nov 18, 2024
Data Sourced
via Red Hat·12:01 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2326972?

The severity of REDHAT-BUG-2326972 is currently rated as critical due to the potential impacts on authentication security in Apache Tomcat.

2

How do I fix REDHAT-BUG-2326972?

To fix REDHAT-BUG-2326972, ensure that any custom Jakarta Authentication ServerAuthContext components correctly handle exceptions and explicitly set an HTTP status on failure.

3

What versions of Apache Tomcat are affected by REDHAT-BUG-2326972?

Apache Tomcat versions 11.0.0-M1 to 11.0.0-M26, 10.1.0-M1 to 10.1.30, and 9.0.0-M1 to 9.0.95 are affected by REDHAT-BUG-2326972.

4

What components are involved in REDHAT-BUG-2326972?

REDHAT-BUG-2326972 involves the Jakarta Authentication ServerAuthContext component within Apache Tomcat.

5

What could happen if REDHAT-BUG-2326972 is exploited?

If REDHAT-BUG-2326972 is exploited, it could lead to unhandled authentication failures, potentially allowing unauthorized access to the application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203