REDHAT-BUG-2476516: Medium severity Apache Tomcat vulnerability
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2476516?
The severity of REDHAT-BUG-2476516 is classified as medium (4).
How does REDHAT-BUG-2476516 affect Apache Tomcat?
REDHAT-BUG-2476516 exposes the HTTP Authentication Header to unexpected hosts during WebSocket authentication in affected versions of Apache Tomcat.
Which versions of Apache Tomcat does REDHAT-BUG-2476516 impact?
REDHAT-BUG-2476516 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.2 through 9.0.117, 8.5.24 through 8.5.100, and 7.0.83 through the latest.
How do I fix REDHAT-BUG-2476516?
To fix REDHAT-BUG-2476516, upgrade your Apache Tomcat installation to a version that is not affected by this vulnerability.
What type of vulnerability is REDHAT-BUG-2476516?
REDHAT-BUG-2476516 is categorized as a WebSocket authentication vulnerability related to HTTP header exposure.