CVE-2023-41080: Apache Tomcat: Open redirect with FORM authentication
Apache Tomcat could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in the FORM authentication feature. An attacker could exploit this vulnerability using a specially crafted URL to redirect a victim to arbitrary Web sites.
Other sources
If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.
https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f https://github.com/advisories/GHSA-q3mw-pvr8-9ggc
— Red Hat
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected.
The vulnerability is limited to the ROOT (default) web application.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41080.
What is the severity of CVE-2023-41080?
The severity of CVE-2023-41080 is medium with a severity value of 6.1.
How does CVE-2023-41080 impact Apache Tomcat?
CVE-2023-41080 allows for URL redirection to untrusted sites, posing a risk to the security of Apache Tomcat.
Which versions of Apache Tomcat are affected by CVE-2023-41080?
CVE-2023-41080 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79, and from 8.5.0 through 8.5.92.
How can I fix or mitigate CVE-2023-41080?
To fix CVE-2023-41080, upgrade Apache Tomcat to versions 8.5.93, 9.0.80, 10.1.13, or 11.0.0-M11, depending on the affected version.