Search CVE reports


Toggle filters

31 – 40 of 69 results


CVE-2023-41080

Medium priority

Some fixes available 3 of 13

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Vulnerable
tomcat8 Not in release Not in release Not in release Vulnerable
tomcat9 Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-34981

Medium priority
Ignored

A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant...

4 affected packages

tomcat8, tomcat9, tomcat6, tomcat7

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat8 Not in release Not in release Not in release Not affected
tomcat9 Not affected Not affected Not affected Not affected
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not affected
Show less packages

CVE-2023-28709

Medium priority
Needs evaluation

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that...

1 affected package

tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-28708

Medium priority

Some fixes available 7 of 13

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to...

3 affected packages

tomcat10, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat10 Not affected Not in release Not in release Not in release
tomcat8 Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-45143

Medium priority
Vulnerable

The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was...

2 affected packages

tomcat9, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Not affected Vulnerable Not affected Not affected
tomcat8 Not in release Not in release Not affected
Show less packages

CVE-2022-42252

Medium priority

Some fixes available 4 of 6

If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat7 Not in release Not in release Not affected
tomcat8 Not in release Not in release Fixed
tomcat9 Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-4132

Medium priority
Ignored

A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page).

4 affected packages

tomcat6, tomcat9, tomcat7, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release
tomcat9 Not affected Not affected Not affected Not affected
tomcat7 Not in release Not in release Not affected
tomcat8 Not in release Not in release Not affected
Show less packages

CVE-2022-34305

Low priority
Vulnerable

In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS...

4 affected packages

tomcat6, tomcat7, tomcat8, tomcat9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Needs evaluation
tomcat8 Not in release Not in release Not in release Not affected
tomcat9 Not affected Vulnerable Vulnerable Not affected
Show less packages

CVE-2022-29885

Low priority

Some fixes available 4 of 5

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network....

2 affected packages

tomcat9, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Not affected Fixed Fixed Fixed
tomcat8 Fixed
Show less packages

CVE-2022-25762

Medium priority
Vulnerable

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue...

2 affected packages

tomcat9, tomcat8

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat9 Not affected Not affected Not affected Vulnerable
tomcat8 Vulnerable
Show less packages