CVE-2024-52316
published 2024-11-18CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext…
PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.29%
92.8th percentile
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.31 | 10.1.31 |
| apache | tomcat | >= 9.0.0 < 9.0.96 | 9.0.96 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.30 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M26 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.95 | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.34-0+deb12u1 (bookworm) | tomcat10 10.1.34-0+deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Authentication bypass occurs when a custom Jakarta Authentication (JASPIC) ServerAuthContext component throws an exception during authentication without explicitly setting an HTTP status to indicate failure — monitor for unexpected successful authentication responses (HTTP 200/302) following exception conditions in Tomcat auth logs ↗
- →Scope of exploitation is limited to Tomcat instances explicitly configured with a custom Jakarta Authentication ServerAuthContext — detection should focus on identifying such configurations in server.xml or application deployment descriptors ↗
- →Exploitation requires a custom ServerAuthContext component that mishandles exceptions — audit deployed JASPIC/Jakarta Authentication modules for improper exception handling that does not set HTTP failure status codes ↗
- ·Vulnerability only affects Tomcat instances explicitly configured to use a custom Jakarta Authentication (JASPIC) ServerAuthContext component; default Tomcat configurations are not affected ↗
- ·Affected versions span Apache Tomcat 9.0.0-M1 through 9.0.95, 10.1.0-M1 through 10.1.30, 11.0.0-M1 through 11.0.0-M26, and EOL branch 8.5.0 through 8.5.100; fixed in 9.0.96, 10.1.31, and 11.0.0 ↗
- ·Red Hat assesses Attack Complexity as High due to the multiple unlikely preconditions required for exploitation, rating all affected Red Hat products as Low severity despite a worst-case Important base flaw rating ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-08-20·CVSS 9.8
CVE-2024-50379 [CRITICAL] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could
Oracle
Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) — CVE-2024-52316
vendor_oracle·2025-04-15·CVSS 9.8
CVE-2024-52316 [CRITICAL] Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) — CVE-2024-52316
Oracle Oracle Hospitality Applications Risk Matrix: Next-Gen SPMS (Apache Tomcat) vulnerability
CVE: CVE-2024-52316
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Red Hat
tomcat: Apache Tomcat: Authentication bypass when using Jakarta Authentication API
vendor_redhat·2024-11-18·CVSS 9.8
CVE-2024-52316 [CRITICAL] CWE-248 tomcat: Apache Tomcat: Authentication bypass when using Jakarta Authentication API
tomcat: Apache Tomcat: Authentication bypass when using Jakarta Authentication API
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other EOL
Debian
CVE-2024-52316: tomcat10 - Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configure...
vendor_debian·2024·CVSS 9.8
CVE-2024-52316 [CRITICAL] CVE-2024-52316: tomcat10 - Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configure...
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0,
OSV
tomcat10 vulnerabilities
osv·2025-08-20·CVSS 9.8
CVE-2025-46701 [CRITICAL] tomcat10 vulnerabilities
tomcat10 vulnerabilities
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could possibly use this
issue to cause a denial of service. This i
GHSA
Apache Tomcat - Authentication Bypass
ghsa·2024-11-18
CVE-2024-52316 [CRITICAL] CWE-391 Apache Tomcat - Authentication Bypass
Apache Tomcat - Authentication Bypass
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100.
Users are recommended to upgrade to version 11.0.0,
OSV
Apache Tomcat - Authentication Bypass
osv·2024-11-18
CVE-2024-52316 [CRITICAL] Apache Tomcat - Authentication Bypass
Apache Tomcat - Authentication Bypass
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100.
Users are recommended to upgrade to version 11.0.0,
OSV
CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat
osv·2024-11-18·CVSS 9.8
CVE-2024-52316 [CRITICAL] CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0,
No detection rules found.
No public exploits indexed.
2024-11-18
Published