Apache Tomcat: Open redirect with FORM authentication
Vulnerability Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-41080
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This vulnerability was reported responsibly to the Tomcat security team by Yiheng Cao.
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →