QID 730770
Date Published: 2023-03-27
QID 730770: Apache Tomcat information disclosure Vulnerability (CVE-2023-28708)
Apache Tomcat is an open source web server and servlet container developed by the Apache Software Foundation.
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Tomcat did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Affected versions:
Apache Tomcat 10.1.0-M1 to 10.1.5
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request to an invalid URL and based on the response confirms the vulnerable instance of Apache Tomcat running on the host.
Successful exploitation of this vulnerability could reveal sensitive information to an unauthorized attacker.
- Apache_Tomcat_10.1.6 -
tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.6
CVEs related to QID 730770
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache Tomcat |
|