Session Fixation vulnerability in Apache Tomcat via rewrite valve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tomcat | Apache | 9.0.1 (including) | 9.0.106 (excluding) |
Tomcat | Apache | 10.0.0 (including) | 10.1.42 (excluding) |
Tomcat | Apache | 11.0.0 (including) | 11.0.8 (excluding) |
Tomcat | Apache | 9.0.0-milestone1 (including) | 9.0.0-milestone1 (including) |
Tomcat | Apache | 9.0.0-milestone10 (including) | 9.0.0-milestone10 (including) |
Tomcat | Apache | 9.0.0-milestone11 (including) | 9.0.0-milestone11 (including) |
Tomcat | Apache | 9.0.0-milestone12 (including) | 9.0.0-milestone12 (including) |
Tomcat | Apache | 9.0.0-milestone13 (including) | 9.0.0-milestone13 (including) |
Tomcat | Apache | 9.0.0-milestone14 (including) | 9.0.0-milestone14 (including) |
Tomcat | Apache | 9.0.0-milestone15 (including) | 9.0.0-milestone15 (including) |
Tomcat | Apache | 9.0.0-milestone16 (including) | 9.0.0-milestone16 (including) |
Tomcat | Apache | 9.0.0-milestone17 (including) | 9.0.0-milestone17 (including) |
Tomcat | Apache | 9.0.0-milestone18 (including) | 9.0.0-milestone18 (including) |
Tomcat | Apache | 9.0.0-milestone19 (including) | 9.0.0-milestone19 (including) |
Tomcat | Apache | 9.0.0-milestone2 (including) | 9.0.0-milestone2 (including) |
Tomcat | Apache | 9.0.0-milestone20 (including) | 9.0.0-milestone20 (including) |
Tomcat | Apache | 9.0.0-milestone21 (including) | 9.0.0-milestone21 (including) |
Tomcat | Apache | 9.0.0-milestone22 (including) | 9.0.0-milestone22 (including) |
Tomcat | Apache | 9.0.0-milestone23 (including) | 9.0.0-milestone23 (including) |
Tomcat | Apache | 9.0.0-milestone24 (including) | 9.0.0-milestone24 (including) |
Tomcat | Apache | 9.0.0-milestone25 (including) | 9.0.0-milestone25 (including) |
Tomcat | Apache | 9.0.0-milestone26 (including) | 9.0.0-milestone26 (including) |
Tomcat | Apache | 9.0.0-milestone27 (including) | 9.0.0-milestone27 (including) |
Tomcat | Apache | 9.0.0-milestone3 (including) | 9.0.0-milestone3 (including) |
Tomcat | Apache | 9.0.0-milestone4 (including) | 9.0.0-milestone4 (including) |
Tomcat | Apache | 9.0.0-milestone5 (including) | 9.0.0-milestone5 (including) |
Tomcat | Apache | 9.0.0-milestone6 (including) | 9.0.0-milestone6 (including) |
Tomcat | Apache | 9.0.0-milestone7 (including) | 9.0.0-milestone7 (including) |
Tomcat | Apache | 9.0.0-milestone8 (including) | 9.0.0-milestone8 (including) |
Tomcat | Apache | 9.0.0-milestone9 (including) | 9.0.0-milestone9 (including) |
Tomcat10 | Ubuntu | devel | * |
Tomcat10 | Ubuntu | esm-apps/noble | * |
Tomcat10 | Ubuntu | noble | * |
Tomcat10 | Ubuntu | plucky | * |
Tomcat10 | Ubuntu | upstream | * |
Tomcat11 | Ubuntu | devel | * |
Tomcat11 | Ubuntu | upstream | * |
Tomcat9 | Ubuntu | esm-apps/bionic | * |
Tomcat9 | Ubuntu | esm-apps/focal | * |
Tomcat9 | Ubuntu | esm-apps/jammy | * |
Tomcat9 | Ubuntu | jammy | * |
Tomcat9 | Ubuntu | upstream | * |
Such a scenario is commonly observed when: