UBUNTU-CVE-2023-28708
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-28708
UBUNTU-CVE-2023-28708
Summary:
Details: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.
References: https://ubuntu.com/security/CVE-2023-28708, https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67, https://www.cve.org/CVERecord?id=CVE-2023-28708, https://ubuntu.com/security/notices/USN-7106-1, https://ubuntu.com/security/notices/USN-7562-1
Affected packages
Package
Name: tomcat7
Purl: pkg:deb/ubuntu/tomcat7?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
