PT-2023-21918 · Apache+9 · Apache Tomcat+9

Mark Thomas

·

Published

2023-02-24

·

Updated

2026-05-18

·

CVE-2023-28708

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.0-M2 Apache Tomcat versions 10.1.0-M1 through 10.1.5 Apache Tomcat versions 9.0.0-M1 through 9.0.71 Apache Tomcat versions 8.5.0 through 8.5.85
Description When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Recommendations For Apache Tomcat versions 11.0.0-M1 through 11.0.0-M2, update to a version that includes the fix for this issue. For Apache Tomcat versions 10.1.0-M1 through 10.1.5, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.0-M1 through 9.0.71, update to a version that includes the fix for this issue. For Apache Tomcat versions 8.5.0 through 8.5.85, update to a version that includes the fix for this issue. As a temporary workaround, consider disabling the RemoteIpFilter until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6570
ALSA-2023:7065
ALT-PU-2023-8058
ALT-PU-2024-4687
ALT-PU-2024-4975
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2025-10838
BIT-TOMCAT-2023-28708
CESA-2023_7065
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-GR86205
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CVE-2023-28708
DLA-3384-1
DSA-5381-1
GHSA-2C9M-W27F-53RM
MGASA-2023-0138
OESA-2023-1247
OPENSUSE-SU-2024:12821-1
OPENSUSE-SU-2024:13441-1
RHSA-2023:4909
RHSA-2023:6570
RHSA-2023:7065
RHSA-2023_6570
RHSA-2023_7065
ROSA-SA-2023-2258
SUSE-SU-2023:1669-1
SUSE-SU-2023:1672-1
SUSE-SU-2023:1769-1
SUSE-SU-2023_1669-1
SUSE-SU-2023_1672-1
SUSE-SU-2026:1058-1
USN-7106-1
USN-7562-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Suse
Ubuntu