CVE-2023-45648
published 2023-10-10CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81…
PriorityP343medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EXPLOIT
EPSS
5.85%
92.3th percentile
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially
crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.1 < 10.1.14 | 10.1.14 |
| apache | tomcat | >= 8.5.0 < 8.5.94 | 8.5.94 |
| apache | tomcat | >= 9.0.1 < 9.0.81 | 9.0.81 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.13 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M11 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.93 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.81 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u1 (bookworm) | tomcat10 10.1.6-1+deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack vector is a specially crafted, invalid HTTP trailer header that causes Tomcat to treat a single request as multiple requests (request smuggling). Detection should focus on malformed or unexpected trailer headers in HTTP/1.1 chunked-encoding requests forwarded through a reverse proxy. ↗
- →Shodan query 'title:"Apache Tomcat"' and FOFA query 'app="APACHE-Tomcat"' can be used to identify internet-exposed Tomcat instances for version-based triage. ↗
- →The fix was introduced in commit 59583245 for the 8.5.x branch. Absence of this commit in a deployed Tomcat instance confirms vulnerability. ↗
- →Qualys WAS QID 150732 detects vulnerable Apache Tomcat versions for CVE-2023-45648 (alongside CVE-2023-42795 and CVE-2023-44487) based on installed version. ↗
- ·Exploitation requires the Tomcat instance to be deployed behind a reverse proxy. A standalone Tomcat deployment without a reverse proxy in front is not exploitable for request smuggling via this vulnerability. ↗
- ·The request smuggling is not guaranteed to carry sensitive data in every smuggled request, and the reverse proxy must also fail to handle the malformed request correctly, reducing real-world exploitability. ↗
- ·Older, end-of-life Tomcat versions beyond the explicitly listed ranges may also be affected and should be treated as vulnerable. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_apache5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
OSV
tomcat9 vulnerabilities
osv·2024-11-13·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat9 vulnerabilities
tomcat9 vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A
remote attacke
OSV
Apache Tomcat Improper Input Validation vulnerability
osv·2023-10-10
CVE-2023-45648 [MEDIUM] Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
OSV
CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat
osv·2023-10-10·CVSS 5.3
CVE-2023-45648 [MEDIUM] CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
GHSA
Apache Tomcat Improper Input Validation vulnerability
ghsa·2023-10-10
CVE-2023-45648 [MEDIUM] CWE-20 Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2024-11-13·CVSS 4.3
CVE-2023-45648 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a
reverse proxy. An attacker could possibly use this issue to leak
sensitive information. (CVE-2023-28708)
It was discovered that Tomcat had a vulnerability in its FORM
authentication feature, leading to an open redirect attack. An attacker
could possibly use this issue to perform phishing attacks. (CVE-2023-41080)
It was discovered that Tomcat incorrectly recycled certain objects,
which could lead to information leaking from one request to the next.
An attacker could potentially use this issue to leak sensitive
information. (CVE-2023-42795)
It was discovered that Tom
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Oracle
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Tomcat) — CVE-2023-45648
vendor_oracle·2024-01-15·CVSS 5.3
CVE-2023-45648 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Tomcat) — CVE-2023-45648
Oracle Oracle Communications Applications Risk Matrix: PSR Designer (Apache Tomcat) vulnerability
CVE: CVE-2023-45648
CVSS: 5.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
tomcat: incorrectly parsed http trailer headers can cause request smuggling
vendor_redhat·2023-10-10·CVSS 5.3
CVE-2023-45648 [MEDIUM] CWE-20 tomcat: incorrectly parsed http trailer headers can cause request smuggling
tomcat: incorrectly parsed http trailer headers can cause request smuggling
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially
crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
A flaw was found in Apache Tomcat, where an improper input validation can occur. This flaw allows a malicious user to sen
Debian
CVE-2023-45648: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t...
vendor_debian·2023·CVSS 5.3
CVE-2023-45648 [MEDIUM] CVE-2023-45648: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t...
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u1)
forky: resolved (fixed in 10.1.14-1)
sid: resolved (fixed in 10.1.14-1)
trixie: resolved (fixed in 10.1.14-1)
Apache
Apache tomcat: CVE-2023-45648
vendor_apache·CVSS 5.3
CVE-2023-45648 [MEDIUM] Apache tomcat: CVE-2023-45648
Apache tomcat: CVE-2023-45648
Tomcat did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. This was fixed with commit 59583245 . This issue was reported to the Tomcat Security Team on 12 September 2023. The issue was made public on 10 October 2023. Affects: 8.5.0 to 8.5.93 Important: Denial of Service
No detection rules found.
Nuclei
Apache Tomcat - HTTP Request Smuggling
nuclei·CVSS 5.3
CVE-2023-45648 [MEDIUM] Apache Tomcat - HTTP Request Smuggling
Apache Tomcat - HTTP Request Smuggling
Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13, and 11.0.0-M1 to 11.0.0-M11 contain an improper input validation caused by incorrect parsing of HTTP trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer headers.
Template:
id: CVE-2023-45648
info:
name: Apache Tomcat - HTTP Request Smuggling
author: 0x_Akoko
severity: medium
description: |
Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13, and 11.0.0-M1 to 11.0.0-M11 contain an improper input validation caused by incorrect parsing of HTTP trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer hea
HackerOne
Request Smuggling in Apache Tomcat (Important, CVE-2023-45648)
hackerone·2024-02-07·CVSS 5.3
CVE-2023-45648 [MEDIUM] Request Smuggling in Apache Tomcat (Important, CVE-2023-45648)
Request Smuggling in Apache Tomcat (Important, CVE-2023-45648)
Apache Tomcat supports Trailer Section. However, we found that in version prior than 11.0.0-M11, 10.1.13, 9.0.80, 8.5.93, Apache Tomcat cannot properly parse the trailer section if there's no colon in the trailer header's line. It will skip the following lines until the last line with a valid colon-separated key-value header pair, which can be leveraged to perform HTTP request smuggling.
If we send the following payload, the headers of the second request **(Line 12-15)** will be regarded as the trailer section of the first request, while the content of the second request **(Line 17-19)** is processed as the second request. When sending this payload to other HTTP implementations such as NGINX, **Line 12-21** would be the secon
Bugzilla
CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
bugzilla·2023-11-29·CVSS 5.3
CVE-2023-46589 [MEDIUM] CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.0-M10
- Apache Tomcat 10.1.0-M1 through 10.1.15
- Apache Tomcat 9.0.0-M1 through 9.0.82
- Apache Tomcat 8.5.0 through 8.5.95
Description:
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from
11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from
9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly
parse HTTP trailer headers. A trailer header that exceeded the header
size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16
onwards, 9.0.83 onw
Bugzilla
CVE-2023-45648 tomcat: incorrectly parsed http trailer headers can cause request smuggling
bugzilla·2023-10-12·CVSS 5.3
CVE-2023-45648 [MEDIUM] CVE-2023-45648 tomcat: incorrectly parsed http trailer headers can cause request smuggling
CVE-2023-45648 tomcat: incorrectly parsed http trailer headers can cause request smuggling
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially
crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp
http://www.openwall.com/lists/oss-security/2023/10/10/10
https://www.debian.org/s
Qualys
CVE-2023-44487 HTTP/2 Rapid Reset Attack
blogs_qualys·2023-10-10·CVSS 7.5
CVE-2023-44487 [HIGH] CVE-2023-44487 HTTP/2 Rapid Reset Attack
## Table of Contents
What is CVE-2023-44487 HTTP/2 Rapid Reset Attack?
What should organizations do?
How can Qualys Help?
Conclusion
Additional Contributors:
Today, Amazon Web Services , Cloudflare , and Google , in a coordinated announcement, reveal their experiences mitigating powerful HTTP/2-based DDoS attacks utilizing a zero-day technique referred to as ‘Rapid Reset’, documented under the vulnerability identifier CVE-2023-44487. The attack magnitudes reported are astonishing: Amazon mitigated attacks at a rate of 155 million requests per second, Cloudflare at 201 million rps, and Google endured a record-breaking 398 million rps. This vulnerability was under active attack in August.
## What is CVE-2023-44487 HTTP/2 Rapid Reset Attack?
The ‘Rapid Reset’ technique leverages the ‘
https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdphttp://www.openwall.com/lists/oss-security/2023/10/10/10https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdphttps://lists.debian.org/debian-lts-announce/2023/10/msg00020.htmlhttps://security.netapp.com/advisory/ntap-20231103-0007/https://www.debian.org/security/2023/dsa-5521https://www.debian.org/security/2023/dsa-5522
2023-10-10
Published