PT-2023-4582 · Apache+9 · Apache Tomcat+9

Yiheng Cao

·

Published

2023-08-25

·

Updated

2026-03-26

·

CVE-2023-41080

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.92 Apache Tomcat versions 9.0.0-M1 through 9.0.79 Apache Tomcat versions 10.1.0-M1 through 10.0.12 Apache Tomcat versions 11.0.0-M1 through 11.0.0-M10
Description The issue is related to a URL redirection vulnerability in the FORM authentication feature of Apache Tomcat, which can allow a remote attacker to redirect users to an arbitrary URL. This vulnerability is limited to the ROOT (default) web application. If the ROOT web application is configured to use FORM authentication, a specially crafted URL could be used to trigger a redirect to an URL of the attacker's choice.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.92, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 9.0.0-M1 through 9.0.79, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 10.1.0-M1 through 10.0.12, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 11.0.0-M1 through 11.0.0-M10, update to a version outside of this range to resolve the issue. As a temporary workaround, consider disabling the FORM authentication feature in the ROOT web application until a patch is available.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0125
ALSA-2024:0474
ALSA-2024_0125
ALSA-2024_0474
ALSA-2024_1134
ALSA-2024_1444
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_16880
ALSA-2025_3645
ALSA-2025_3683
ALT-PU-2023-8058
ALT-PU-2024-4687
ALT-PU-2024-4975
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2023-04989
BIT-TOMCAT-2023-41080
CESA-2024_0125
CVE-2023-41080
DLA-3617-1
DSA-5521-1
DSA-5522-1
ELSA-2024-0125
ELSA-2024-0474
GHSA-Q3MW-PVR8-9GGC
OESA-2023-1632
OPENSUSE-SU-2024:13256-1
OPENSUSE-SU-2024:13441-1
RHSA-2023:7622
RHSA-2024:0125
RHSA-2024:0474
RHSA-2024:1324
RHSA-2024_0125
RHSA-2024_0474
ROSA-SA-2024-2418
SUSE-SU-2023:3987-1
SUSE-SU-2023:4129-1
SUSE-SU-2023:4423-1
SUSE-SU-2023_3987-1
SUSE-SU-2023_4423-1
SUSE-SU-2026:1058-1
USN-7106-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Suse
Ubuntu