QID 150662
Date Published: 2023-03-30
QID 150662: Apache Tomcat Information Disclosure Vulnerability (CVE-2023-28708)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
Tomcat's RemoteIpFilter, when used with HTTP requests received from a reverse proxy that includes the X-Forwarded-Proto header set to https, may cause session cookies created by Tomcat to be transmitted over an insecure channel if the secure attribute is not included in the cookies. This could potentially expose sensitive user data to attackers.
Affected Versions:
Apache Tomcat 11.0.0-M1 to 11.0.0-M2
Apache Tomcat 10.1.0-M1 to 10.1.5
Apache Tomcat 9.0.0-M1 to 9.0.71
Apache Tomcat 8.5.0 to 8.5.85
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Insecure transmission of session cookies could potentially expose sensitive user data to attackers.
- Apache Tomcat -
lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67
CVEs related to QID 150662
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|