Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-docs-webappUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat | Jan 18, 2024 | Oct 10, 2023 |
| Amazon Linux Ami 2 | — | Upgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-servlet-3.1-apiUpgrade tomcat-jsvcUpgrade tomcat-servlet-3.0-apiUpgrade tomcat-el-2.2-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-jsp-2.2-apiUpgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-javadocUpgrade tomcat-admin-webapps | Oct 18, 2023 | Oct 10, 2023 |
| Amazon_linux | — | Upgrade tomcat8 | Oct 19, 2023 | Oct 10, 2023 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.81Upgrade Apache Tomcat to 8.5.94Upgrade Apache Tomcat to 10.1.14Upgrade Apache Tomcat to 11.0.0 | Oct 11, 2023 | Oct 10, 2023 |
| Centos_linux | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-el-3.0-apiUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat | Jan 11, 2024 | Oct 10, 2023 |
| Debian | — | Upgrade tomcat9Upgrade tomcat10 | Oct 12, 2023 | Oct 10, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade tomcat-el-3.0-apiUpgrade tomcat-servlet-4.0-apiUpgrade tomcatUpgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-api | Mar 13, 2024 | Oct 10, 2023 |
| Oracle_linux | — | Upgrade tomcat-servlet-4.0-apiUpgrade tomcat-docs-webappUpgrade tomcatUpgrade tomcat-el-3.0-apiUpgrade tomcat-webappsUpgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-api | Jan 11, 2024 | Oct 10, 2023 |
| Redhat_linux | — | Upgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-libUpgrade tomcat-webappsUpgrade tomcat-admin-webappsUpgrade tomcat-servlet-4.0-apiNo solution existsUpgrade tomcat-jsp-2.3-api | Jan 11, 2024 | Oct 10, 2023 |
| Suse | — | Upgrade tomcat-servlet-4_0-apiUpgrade tomcat-libUpgrade tomcat-embedUpgrade tomcat-webappsUpgrade tomcat-el-3_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-jsvcUpgrade tomcat-admin-webappsUpgrade tomcat-docs-webappUpgrade tomcat-javadocUpgrade tomcat | Nov 3, 2023 | Oct 10, 2023 |
| Ubuntu | — | Upgrade libtomcat8-java (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro)Upgrade libtomcat10-java (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat9-javaUpgrade tomcat9 | Nov 19, 2024 | Oct 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub