USN-6880-1: Tomcat vulnerability
Published Jul 9, 2024
·Updated
Sam Shahsavar discovered that Apache Tomcat did not properly reject HTTP requests with an invalid Content-Length header. A remote attacker could possibly use this issue to perform HTTP request smuggling attacks.
Affected Software
16 affected componentsFixes available
All of the following
ubuntu/libtomcat9-java<9.0.58-1ubuntu0.1+esm1
9.0.58-1ubuntu0.1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/tomcat9<9.0.58-1ubuntu0.1+esm1
9.0.58-1ubuntu0.1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtomcat9-java<9.0.31-1ubuntu0.5
9.0.31-1ubuntu0.5
Ubuntu Ubuntu=20.04
All of the following
ubuntu/tomcat9<9.0.31-1ubuntu0.5
9.0.31-1ubuntu0.5
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtomcat8-java<8.5.39-1ubuntu1~18.04.3+esm1
8.5.39-1ubuntu1~18.04.3+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtomcat9-java<9.0.16-3ubuntu0.18.04.2+esm1
9.0.16-3ubuntu0.18.04.2+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/tomcat8<8.5.39-1ubuntu1~18.04.3+esm1
8.5.39-1ubuntu1~18.04.3+esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/tomcat9<9.0.16-3ubuntu0.18.04.2+esm1
9.0.16-3ubuntu0.18.04.2+esm1
Ubuntu Ubuntu=18.04
Event History
Jul 9, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6880-1?
The severity of USN-6880-1 is considered moderate due to the potential for HTTP request smuggling attacks.
2
How do I fix USN-6880-1?
To fix USN-6880-1, upgrade to the recommended version of Tomcat provided in the advisory.
3
What are the affected versions in USN-6880-1?
USN-6880-1 affects specific versions of Tomcat 9 and 8 on Ubuntu 18.04 and 22.04.
4
Who discovered the vulnerability in USN-6880-1?
The vulnerability in USN-6880-1 was discovered by Sam Shahsavar.
5
What type of attack is associated with USN-6880-1?
USN-6880-1 is associated with HTTP request smuggling attacks due to improper handling of malformed Content-Length headers.