imPC@ndo IT

Tracker / CVE-2023-41080

CVE-2023-41080

Medium 6.1

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.

Affected products and versions

apache tomcat
apache tomcat · 10.1.0 → 10.1.12
apache tomcat · 8.5.0 → 8.5.92
apache tomcat · 9.0.0 → 9.0.79
debian debian_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References