CVE-2023-28708
published 2023-03-22CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies…
PriorityP422medium4.3CVSS 3.1
AVNACLPRNUIRSUCLINAN
EPSS
1.83%
76.5th percentile
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Older, EOL versions may also be affected.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | < 9.0.72 | 9.0.72 |
| apache | tomcat | < 10.1.6 | 10.1.6 |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 8.5.0 < 8.5.86 | 8.5.86 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.5 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M2 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.85 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.71 | — |
| debian | tomcat10 | < tomcat10 10.1.6-1 (bookworm) | tomcat10 10.1.6-1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1 (bookworm) | tomcat10 10.1.6-1 (bookworm) |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_apache4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_oracle4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
OSV
tomcat9 vulnerabilities
osv·2024-11-13·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A
remote attacke
OSV
CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session coo
osv·2023-03-22·CVSS 4.3
CVE-2023-28708 [MEDIUM] CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session coo
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.
OSV
Apache Tomcat vulnerable to Unprotected Transport of Credentials
osv·2023-03-22
CVE-2023-28708 [MEDIUM] Apache Tomcat vulnerable to Unprotected Transport of Credentials
Apache Tomcat vulnerable to Unprotected Transport of Credentials
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
GHSA
Apache Tomcat vulnerable to Unprotected Transport of Credentials
ghsa·2023-03-22
CVE-2023-28708 [MEDIUM] CWE-523 Apache Tomcat vulnerable to Unprotected Transport of Credentials
Apache Tomcat vulnerable to Unprotected Transport of Credentials
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-11-13·CVSS 4.3
CVE-2023-45648 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tom
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2023-28708
vendor_oracle·2023-10-15·CVSS 4.3
CVE-2023-28708 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) — CVE-2023-28708
Oracle Oracle Fusion Middleware Risk Matrix: MFT Runtime Server (Apache Tomcat) vulnerability
CVE: CVE-2023-28708
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Apache Tomcat) — CVE-2023-28708
vendor_oracle·2023-07-15·CVSS 4.3
CVE-2023-28708 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install/Upgrade (Apache Tomcat) — CVE-2023-28708
Oracle Oracle Communications Risk Matrix: Install/Upgrade (Apache Tomcat) vulnerability
CVE: CVE-2023-28708
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Core (Apache Tomcat) — CVE-2023-28708
vendor_oracle·2023-04-15·CVSS 4.3
CVE-2023-28708 [MEDIUM] Oracle Oracle Communications Risk Matrix: Core (Apache Tomcat) — CVE-2023-28708
Oracle Oracle Communications Risk Matrix: Core (Apache Tomcat) vulnerability
CVE: CVE-2023-28708
CVSS: 4.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Red Hat
tomcat: not including the secure attribute causes information disclosure
vendor_redhat·2023-03-22·CVSS 4.3
CVE-2023-28708 [MEDIUM] CWE-200 tomcat: not including the secure attribute causes information disclosure
tomcat: not including the secure attribute causes information disclosure
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Older, EOL versions may also be affected.
Statement: CVE-2023-28708 only potentially impacts a Tomcat configuration using a RemoteIpFilter behind a proxy or loadbalancer that sets an X-Forwarded-Proto request header with a value of https. If you do not use RemoteIpFilter in such a configuration, then the vulnerability would no
Debian
CVE-2023-28708: tomcat10 - When using the RemoteIpFilter with requests received from a reverse proxy via...
vendor_debian·2023·CVSS 4.3
CVE-2023-28708 [MEDIUM] CVE-2023-28708: tomcat10 - When using the RemoteIpFilter with requests received from a reverse proxy via...
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.
Scope: local
bookworm: resolved (fixed in 10.1.6-1)
forky: resolved (fixed in 10.1.6-1)
sid: resolved (fixed in 10.1.6-1)
trixie: resolved (fixed in 10.1.6-1)
Apache
Apache tomcat: CVE-2023-28708
vendor_apache·CVSS 4.3
CVE-2023-28708 [MEDIUM] Apache tomcat: CVE-2023-28708
Apache tomcat: CVE-2023-28708
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https , session cookies created by Tomcat did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. This was fixed with commit 5b72c94e . 66471 was reported publicly on 8 February 2023. The security implications were identified by the Tomcat Security team on 9 February 2023. The issue was made public on 22 March 2023. Affects: 8.5.0 to 8.5.85 2023-01-19 Fixed in Apache Tomcat 8.5.85 Important: Apache Tomcat denial of service
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-22
Published