GHSA-q3mw-pvr8-9ggc
Dashboard / Vulnerabilities / GHSA-q3mw-pvr8-9ggc
GHSA-q3mw-pvr8-9ggc
Summary: Apache Tomcat Open Redirect vulnerability
Details: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-41080, https://github.com/apache/tomcat/commit/4998ad745b67edeadefe541c94ed029b53933d3b, https://github.com/apache/tomcat/commit/77c0ce2d169efa248b64b992e547aad549ec906b, https://github.com/apache/tomcat/commit/bb4624a9f3e69d495182ebfa68d7983076407a27, https://github.com/apache/tomcat/commit/e3703c9abb8fe0d5602f6ba8a8f11d4b6940815a, https://github.com/apache/tomcat, https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f, https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html, https://security.netapp.com/advisory/ntap-20230921-0006, https://www.debian.org/security/2023/dsa-5521, https://www.debian.org/security/2023/dsa-5522
Affected packages
Package
Name: org.apache.tomcat:tomcat
Purl: pkg:maven/org.apache.tomcat/tomcat
Affected ranges
Type: ECOSYSTEM
Events:
