CVE-2023-41080
Summary
| CVE | CVE-2023-41080 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-25 21:15:00 UTC |
| Updated | 2023-11-03 19:00:00 UTC |
| Description | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-5522-1 tomcat9 |
MISC |
www.debian.org |
|
| CVE-2023-41080 Apache Tomcat Vulnerability in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| [SECURITY] [DLA 3617-1] tomcat9 security update |
MISC |
lists.debian.org |
|
| lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f |
MISC |
lists.apache.org |
|
| Debian -- Security Information -- DSA-5521-1 tomcat10 |
MISC |
www.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161276 Oracle Enterprise Linux Security Update for tomcat (ELSA-2024-0125)
- 161315 Oracle Enterprise Linux Security Update for tomcat (ELSA-2024-0474)
- 242835 Red Hat Update for tomcat (RHSA-2024:0474)
- 242881 Red Hat Update for tomcat (RHSA-2024:0125)
- 356230 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-015
- 356239 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-009
- 356373 Amazon Linux Security Advisory for tomcat9 : ALAS2023-2023-365
- 356454 Amazon Linux Security Advisory for tomcat8 : ALAS-2023-1861
- 6000246 Debian Security Update for tomcat9 (DSA 5522-1)
- 6000247 Debian Security Update for tomcat10 (DSA 5521-1)
- 6000257 Debian Security Update for tomcat9 (DLA 3617-1)
- 674011 EulerOS Security Update for tomcat (EulerOS-SA-2024-1305)
- 755045 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:3987-1)
- 755117 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:4129-1)
- 755250 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2023:4423-1)
- 941533 AlmaLinux Security Update for tomcat (ALSA-2024:0125)
- 941551 AlmaLinux Security Update for tomcat (ALSA-2024:0474)