CVE-2023-28708

MEDIUM

Apache Tomcat <11.0.0-M2 - Info Disclosure

Title source: llm
STIX 2.1

Description

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

References (2)

Core 2
Core References
Mailing List, Patch, Vendor Advisory vendor-advisory
https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67

Scores

CVSS v3 4.3
EPSS 0.0011
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-523
Status published
Products (3)
apache/tomcat 11.0.0 milestone1 (2 CPE variants)
apache/tomcat 8.5.0 - 8.5.86
org.apache.tomcat/tomcat-catalina 11.0.0-M1 - 11.0.0-M3Maven
Published Mar 22, 2023
Tracked Since Feb 18, 2026