
=====================================================================

                              CERT-Renater

                    Note d'Information No. 2023/VULN269

_____________________________________________________________________

DATE                : 29/08/2023

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Apache Tomcat versions prior to
                             11.0.0-M11, 10.1.13, 9.0.80, 8.5.93.

=====================================================================
https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f
_____________________________________________________________________


[SECURITY] CVE-2023-41080 Apache Tomcat - open redirect

Mark Thomas Fri, 25 Aug 2023 10:54:17 -0700

CVE-2023-41080 Apache Tomcat - Open redirect

Severity: Moderate


Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.0-M10
Apache Tomcat 10.1.0-M1 to 10.1.12
Apache Tomcat 9.0.0-M1 to 9.0.79
Apache Tomcat 8.5.0 to 8.5.92

Description:

If the ROOT (default) web application is configured to use FORM
authentication then it is possible that a specially crafted URL could
be used to trigger a redirect to an URL of the attackers choice.


Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.0-M11 or later
- Upgrade to Apache Tomcat 10.1.13 or later
- Upgrade to Apache Tomcat 9.0.80 or later
- Upgrade to Apache Tomcat 8.5.93 or later

Credit:

This vulnerability was reported responsibly to the Tomcat security
team by Yiheng Cao.


History:
2023-08-25 Original advisory


References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html
[4] https://tomcat.apache.org/security-8.html


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================

