URL Redirection to Untrusted Site (Open Redirect) vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.
The vulnerability is limited to the ROOT (default) web application.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 8.5.0 (including) | 8.5.92 (including) |
Tomcat | Apache | 9.0.0 (including) | 9.0.79 (including) |
Tomcat | Apache | 10.1.0 (including) | 10.1.12 (including) |
Tomcat | Apache | 11.0.0-milestone1 (including) | 11.0.0-milestone1 (including) |
Tomcat | Apache | 11.0.0-milestone10 (including) | 11.0.0-milestone10 (including) |
Tomcat | Apache | 11.0.0-milestone2 (including) | 11.0.0-milestone2 (including) |
Tomcat | Apache | 11.0.0-milestone3 (including) | 11.0.0-milestone3 (including) |
Tomcat | Apache | 11.0.0-milestone4 (including) | 11.0.0-milestone4 (including) |
Tomcat | Apache | 11.0.0-milestone5 (including) | 11.0.0-milestone5 (including) |
Tomcat | Apache | 11.0.0-milestone6 (including) | 11.0.0-milestone6 (including) |
Tomcat | Apache | 11.0.0-milestone7 (including) | 11.0.0-milestone7 (including) |
Tomcat | Apache | 11.0.0-milestone8 (including) | 11.0.0-milestone8 (including) |
Tomcat | Apache | 11.0.0-milestone9 (including) | 11.0.0-milestone9 (including) |
JWS 6.0.1 | RedHat | tomcat | * |
Red Hat AMQ Broker 7 | RedHat | tomcat | * |
Red Hat AMQ Streams 2.6.0 | RedHat | tomcat | * |
Red Hat Enterprise Linux 8 | RedHat | tomcat-1:9.0.62-27.el8_9.2 | * |
Red Hat Enterprise Linux 9 | RedHat | tomcat-1:9.0.62-37.el9_3.1 | * |
Red Hat JBoss Web Server 5 | RedHat | tomcat | * |
Red Hat JBoss Web Server 5.7 on RHEL 7 | RedHat | jws5-tomcat-0:9.0.62-19.redhat_00017.1.el7jws | * |
Red Hat JBoss Web Server 5.7 on RHEL 8 | RedHat | jws5-tomcat-0:9.0.62-19.redhat_00017.1.el8jws | * |
Red Hat JBoss Web Server 5.7 on RHEL 9 | RedHat | jws5-tomcat-0:9.0.62-19.redhat_00017.1.el9jws | * |
Red Hat JBoss Web Server 6.0 on RHEL 8 | RedHat | jws6-tomcat-0:10.1.8-6.redhat_00013.1.el8jws | * |
Red Hat JBoss Web Server 6.0 on RHEL 9 | RedHat | jws6-tomcat-0:10.1.8-6.redhat_00013.1.el9jws | * |
Red Hat OpenShift Dev Spaces 3 Containers | RedHat | devspaces/server-rhel8:3.15-3 | * |
Tomcat6 | Ubuntu | trusty | * |
Tomcat6 | Ubuntu | trusty/esm | * |
Tomcat6 | Ubuntu | xenial | * |
Tomcat7 | Ubuntu | bionic | * |
Tomcat7 | Ubuntu | trusty | * |
Tomcat7 | Ubuntu | trusty/esm | * |
Tomcat7 | Ubuntu | xenial | * |
Tomcat8 | Ubuntu | bionic | * |
Tomcat8 | Ubuntu | xenial | * |
Tomcat9 | Ubuntu | bionic | * |
Tomcat9 | Ubuntu | esm-apps/bionic | * |
Tomcat9 | Ubuntu | esm-apps/jammy | * |
Tomcat9 | Ubuntu | focal | * |
Tomcat9 | Ubuntu | lunar | * |
Tomcat9 | Ubuntu | mantic | * |