7.5
CVSSv3

CVE-2023-46589

Published: 28/11/2023 Updated: 21/11/2024

Vulnerability Summary

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 up to and including 11.0.0-M10, from 10.1.0-M1 up to and including 10.1.15, from 9.0.0-M1 up to and including 9.0.82 and from 8.5.0 up to and including 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache tomcat

apache tomcat 11.0.0

Vendor Advisories

概要 Important: tomcat security update タイプ/重大度 Security Advisory: Important Red Hat Insights パッチ分析 このアドバイザリーの影響を受けるシステムを特定し、修正します。 影響を受けるシステムの表示 トピック An update for tomcat is now available for Red Hat Enterprise Lin ...
Synopsis Important: tomcat security update Type / Sévérité Security Advisory: Important Analyse des correctifs dans Red Hat Insights Identifiez et remédiez aux systèmes concernés par cette alerte Voir les systèmes concernés Sujet An update for tomcat is now available for Red Hat Enterprise Linux 8Red Hat Product Security h ...
Debian Bug report logs - #1057082 tomcat10: CVE-2023-46589 Package: src:tomcat10; Maintainer for src:tomcat10 is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 29 Nov 2023 12:12:01 UTC Severity: important Tags: fixed-upstream, s ...
Improper Input Validation vulnerability in Apache TomcatTomcat from 1100-M1 through 1100-M10, from 1010-M1 through 10115, from 900-M1 through 9082 and from 850 through 8595 did not correctly parse HTTP trailer headers A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requ ...
Improper Input Validation vulnerability in Apache TomcatTomcat from 1100-M1 through 1100-M10, from 1010-M1 through 10115, from 900-M1 through 9082 and from 850 through 8595 did not correctly parse HTTP trailer headers A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requ ...
Vulnerability (CVE-2023-46589) have been found in Cosminexus Affected products and versions are listed below Please upgrade your version to the appropriate version This vulnerability does not occur on systems where Cosminexus HTTP Server is placed in front of the J2EE server as a reverse proxy Also, this does not occur when the J2EE server i ...
Hitachi Ops Center Administrator contains the following vulnerabilities: CVE-2023-45648, CVE-2023-46589, CVE-2023-46604 Affected products and versions are listed below Please upgrade your version to the appropriate version ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2020-8908, CVE-2023-0481, CVE-2023-2976, CVE-2023-3635, CVE-2023-4853, CVE-2023-33202, CVE-2023-34054, CVE-2023-34062, CVE-2023-34462, CVE-2023-42795, CVE-2023-45648, CVE-2023-46589 ...

Mailing Lists

Severity: important Affected versions: - Apache Tomcat 1100-M1 through 1100-M10 - Apache Tomcat 1010-M1 through 10115 - Apache Tomcat 900-M1 through 9082 - Apache Tomcat 850 through 8595 Description: request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy Credit: Norihito Ai ...

Github Repositories

This is a sample for deploying a Spring Boot application in an environment built with Docker and Ansible.

Docker and Ansible Sample 1 This is a sample for deploying a Spring Boot application in an environment built with Docker and Ansible The environment is constructed using versions that contain vulnerabilities Components Component Version Vulnerability Note Apache 2460 wwwcveorg/CVERecord?id=CVE-2024-39884 Tomcat 10115 wwwcveorg/CVERecord?id=CV

Docker and Ansible Sample 1 This is a sample for deploying a Spring Boot application in an environment built with Docker and Ansible The environment is constructed using versions that contain vulnerabilities Components Component Version Vulnerability Note Apache 2460 wwwcveorg/CVERecord?id=CVE-2024-39884 Tomcat 10115 wwwcveorg/CVERecord?id=CV