PT-2024-8689 · Apache+4 · Apache Tomcat+4

Mark Thomas

·

Published

2024-02-03

·

Updated

2026-04-28

·

CVE-2024-52316

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.0-M26 Apache Tomcat versions 10.1.0-M1 through 10.1.30 Apache Tomcat versions 9.0.0-M1 through 9.0.95
Description The issue is related to an Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication ServerAuthContext component that may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This vulnerability could potentially allow a remote attacker to bypass the authentication process and cause a denial of service.
Recommendations To resolve the issue, upgrade to version 11.0.0, 10.1.31, or 9.0.96, which fix the issue. For versions 11.0.0-M1 through 11.0.0-M26, upgrade to version 11.0.0. For versions 10.1.0-M1 through 10.1.30, upgrade to version 10.1.31. For versions 9.0.0-M1 through 9.0.95, upgrade to version 9.0.96.

Exploit

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:7497
ALT-PU-2025-13307
ALT-PU-2025-1726
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2024-10291
BIT-TOMCAT-2024-52316
CVE-2024-52316
DLA-4017-1
DSA-5845-1
GHSA-XCPR-7MR4-H4XQ
MGASA-2024-0379
OPENSUSE-SU-2024:14525-1
OPENSUSE-SU-2024:14526-1
OPENSUSE-SU-2024_4105-1
OPENSUSE-SU-2024_4106-1
RHSA-2025:3608
RHSA-2025:7497
SUSE-SU-2024:4075-1
SUSE-SU-2024:4105-1
SUSE-SU-2024:4106-1
SUSE-SU-2024_4075-1
SUSE-SU-2024_4105-1
SUSE-SU-2024_4106-1
SUSE-SU-2026:1058-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Red Os
Suse