CVE-2023-41080: Apache Tomcat: Open redirect with FORM authentication
If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.
https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f https://github.com/advisories/GHSA-q3mw-pvr8-9ggc
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected.
The vulnerability is limited to the ROOT (default) web application.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 11.0.0-M11 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 10.1.13 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.80 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.93 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 8.5.93 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 9.0.80 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 10.1.13 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcatto a version that resolves this vulnerability.Fixed in 11.0.0-M11 - Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.6-1+deb12u1Fixed in 10.1.16-1 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.31-1~deb10u10Fixed in 9.0.43-2~deb11u9Fixed in 9.0.70-2 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 11.0.0 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 10.1.13 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.80 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.93 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 8.5.93 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 9.0.80 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 10.1.13
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41080.
What is the severity of CVE-2023-41080?
The severity of CVE-2023-41080 is medium with a severity value of 6.1.
How does CVE-2023-41080 impact Apache Tomcat?
CVE-2023-41080 allows for URL redirection to untrusted sites, posing a risk to the security of Apache Tomcat.
Which versions of Apache Tomcat are affected by CVE-2023-41080?
CVE-2023-41080 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79, and from 8.5.0 through 8.5.92.
How can I fix or mitigate CVE-2023-41080?
To fix CVE-2023-41080, upgrade Apache Tomcat to versions 8.5.93, 9.0.80, 10.1.13, or 11.0.0-M11, depending on the affected version.