QID 150662

Date Published: 2023-03-30

QID 150662: Apache Tomcat Information Disclosure Vulnerability (CVE-2023-28708)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

Tomcat's RemoteIpFilter, when used with HTTP requests received from a reverse proxy that includes the X-Forwarded-Proto header set to https, may cause session cookies created by Tomcat to be transmitted over an insecure channel if the secure attribute is not included in the cookies. This could potentially expose sensitive user data to attackers.

Affected Versions:
Apache Tomcat 11.0.0-M1 to 11.0.0-M2
Apache Tomcat 10.1.0-M1 to 10.1.5
Apache Tomcat 9.0.0-M1 to 9.0.71
Apache Tomcat 8.5.0 to 8.5.85

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.

Insecure transmission of session cookies could potentially expose sensitive user data to attackers.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    To address this vulnerability, it is recommended that customers upgrade to one of the following versions of Apache Tomcat: 11.0.0-M3, 10.1.6, 9.0.72, or 8.5.86, or install a newer version. For additional information, please refer to the Apache Tomcat Security Advisory.

    CVEs related to QID 150662

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat URL Logo lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67