Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.2, <= 9.0.117
- >= 8.5.24, <= 8.5.100
- >= 7.0.83, <= 7.0.109
A vulnerability exists in Apache Tomcat's WebSocket implementation, where the HTTP authentication header can be exposed to unintended hosts during the authentication process. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.2 prior to 9.0.117, 8.5.24 prior to 8.5.100, and 7.0.83 prior to 7.0.109. Users of these versions are advised to upgrade to Tomcat 11.0.22, 10.1.55, or 9.0.118, which address this vulnerability.
Exploitation of this vulnerability could lead to the unintended exposure of HTTP authentication credentials to a redirect target host during WebSocket communication.
Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.