QID 150755

Date Published: 2023-12-06

QID 150755: Apache Tomcat Request Smuggling Vulnerability (CVE-2023-46589)

Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.

Tomcat did not correctly parse HTTP trailer headers. A specially crafted trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.

Affected Versions:
Apache Tomcat 11.0.0-M1 to 11.0.0-M10
Apache Tomcat 10.1.0-M1 to 10.1.15
Apache Tomcat 9.0.0-M1 to 9.0.82
Apache Tomcat 8.5.0 to 8.5.95

QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to a invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.

Exploitation of the vulnerability could lead to HTTP request smuggling attack.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution
    Customers are advised to upgrade relevant versions of Apache Tomcat:
    Apache Tomcat 11.0.0-M11 or later
    Apache Tomcat 10.1.16 or later
    Apache Tomcat 9.0.83 or later
    Apache Tomcat 8.5.96 or later
    For more information on this vulnerability please refer Apache Tomcat 8 Security Advisory, Apache Tomcat 9 Security Advisory, Apache Tomcat 10 Security Advisory, Apache Tomcat 11 Security Advisory.

    CVEs related to QID 150755

    Software Advisories
    Advisory ID Software Component Link
    Apache Tomcat URL Logo lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr