PT-2023-8633 · Apache+11 · Apache Tomcat+13

Norihito Aimoto

·

Publicado

2023-11-13

·

Atualizado

2026-04-28

·

CVE-2023-46589

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.0-M10 Apache Tomcat versions 10.1.0-M1 through 10.1.15 Apache Tomcat versions 9.0.0-M1 through 9.0.82 Apache Tomcat versions 8.5.0 through 8.5.95
Description The issue is related to an Improper Input Validation vulnerability in Apache Tomcat, where Tomcat does not correctly parse HTTP trailer headers. If a trailer header exceeds the header size limit, Tomcat may treat a single request as multiple requests, leading to the possibility of request smuggling when behind a reverse proxy.
Recommendations To resolve the issue, upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards, or 8.5.96 onwards, which fix the issue. For Bitbucket Data Center and Server, upgrade to a release greater than or equal to 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, or 8.16.2. For Bamboo Data Center and Server, upgrade to a release greater than or equal to 9.2.8, 9.3.6, or 9.4.2. As a temporary workaround, consider restricting access to the vulnerable module to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2024:0539
ALSA-2024:1134
ALT-PU-2023-8058
ALT-PU-2024-4687
ALT-PU-2024-4975
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2024-01300
BIT-TOMCAT-2023-46589
CESA-2024_0539
CVE-2023-46589
DLA-3707-1
DSA-5665-1
DSA-5667-1
GHSA-FCCV-JMMP-QG76
OESA-2024-2402
OESA-2024-2403
OESA-2024-2404
OESA-2024-2405
OESA-2024-2460
OPENSUSE-SU-2024:13590-1
OPENSUSE-SU-2024:13596-1
OPENSUSE-SU-2024_0208-1
OPENSUSE-SU-2024_0472-1
RHSA-2024:0532
RHSA-2024:0539
RHSA-2024:1092
RHSA-2024:1134
RHSA-2024:1318
RHSA-2024:1324
RHSA-2024_0539
RHSA-2024_1134
RLSA-2024:0539
ROSA-SA-2024-2544
SUSE-SU-2024:0206-1
SUSE-SU-2024:0208-1
SUSE-SU-2024:0209-1
SUSE-SU-2024:0472-1
SUSE-SU-2024_0206-1
SUSE-SU-2024_0208-1
SUSE-SU-2024_0209-1
SUSE-SU-2026:1058-1
USN-7032-1

Produtos afetados

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Bamboo
Bitbucket
Centos
Confluence
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu