CVE-2023-46589: Apache Tomcat: HTTP request smuggling via malformed trailer headers
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.0-M10 - Apache Tomcat 10.1.0-M1 through 10.1.15 - Apache Tomcat 9.0.0-M1 through 9.0.82 - Apache Tomcat 8.5.0 through 8.5.95
Description:
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
Credit:
Norihito Aimoto (OSSTech Corporation) (finder)
References:
https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr http://www.openwall.com/lists/oss-security/2023/11/28/2
Other sources
Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82, and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
— GitHub
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.96 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.83 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 10.1.16 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 11.0.0-M11 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 8.5.96 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 9.0.83 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 10.1.16 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-catalinato a version that resolves this vulnerability.Fixed in 11.0.0-M11 - Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.6-1+deb12u2Fixed in 10.1.30-1 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.43-2~deb11u10Fixed in 9.0.70-2 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 9.0.83 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.0-M11 onwards - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.16 onwards - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.83 onwards - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 8.5.96 onwards
Event History
Frequently Asked Questions
What is CVE-2023-46589?
CVE-2023-46589 is an Improper Input Validation vulnerability in Apache Tomcat that allows for HTTP request smuggling via malformed trailer headers.
How does CVE-2023-46589 affect Apache Tomcat?
CVE-2023-46589 affects Apache Tomcat versions 8.5.0 through 8.5.95, 9.0.0-M1 through 9.0.82, 10.1.0-M1 through 10.1.15, and 11.0.0-M1 through 11.0.0-M10.
What is the remedy for CVE-2023-46589 in Apache Tomcat version 8.5.96?
The remedy for CVE-2023-46589 in Apache Tomcat version 8.5.96 is to update to that specific version or a later version.
What is the remedy for CVE-2023-46589 in Apache Tomcat version 9.0.83?
The remedy for CVE-2023-46589 in Apache Tomcat version 9.0.83 is to update to that specific version or a later version.
What is the remedy for CVE-2023-46589 in Apache Tomcat version 10.1.16?
The remedy for CVE-2023-46589 in Apache Tomcat version 10.1.16 is to update to that specific version or a later version.
What is the remedy for CVE-2023-46589 in Apache Tomcat version 11.0.0-M11?
The remedy for CVE-2023-46589 in Apache Tomcat version 11.0.0-M11 is to update to that specific version or a later version.