Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-libUpgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webapps | Jan 18, 2024 | Oct 10, 2023 |
| Amazon Linux Ami 2 | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.2-apiUpgrade tomcat-el-2.2-apiUpgrade tomcat-javadocUpgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-docs-webappUpgrade tomcat-jsvcUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-libUpgrade tomcat-webappsUpgrade tomcat-servlet-3.0-api | Oct 18, 2023 | Oct 10, 2023 |
| Amazon_linux | — | Upgrade tomcat8 | Oct 19, 2023 | Oct 10, 2023 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 10.1.14Upgrade Apache Tomcat to 8.5.94Upgrade Apache Tomcat to 11.0.0Upgrade Apache Tomcat to 9.0.81Upgrade Apache Tomcat to the latest available version | Oct 11, 2023 | Oct 10, 2023 |
| Centos_linux | — | Upgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-libUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-api | Jan 11, 2024 | Oct 10, 2023 |
| Debian | — | Upgrade tomcat10Upgrade tomcat9 | Oct 12, 2023 | Oct 10, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-jsp-2.3-api | Mar 13, 2024 | Oct 10, 2023 |
| Oracle_linux | — | Upgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-apiUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-webappsUpgrade tomcat-el-3.0-api | Jan 11, 2024 | Oct 10, 2023 |
| Redhat_linux | — | Upgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-admin-webappsNo solution existsUpgrade tomcat-webapps | Jan 11, 2024 | Oct 10, 2023 |
| Suse | — | Upgrade tomcat-servlet-4_0-apiUpgrade tomcat-embedUpgrade tomcat-libUpgrade tomcat-el-3_0-apiUpgrade tomcat-admin-webappsUpgrade tomcat-jsvcUpgrade tomcat-webappsUpgrade tomcat-javadocUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-docs-webappUpgrade tomcat | Nov 3, 2023 | Oct 10, 2023 |
| Ubuntu | — | Upgrade libtomcat9-javaUpgrade tomcat9Upgrade libtomcat10-java (Ubuntu Pro)Upgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro) | Nov 19, 2024 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub