cbcvebase.
CVE-2024-52316
published 2024-11-18

CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext…

PriorityP270critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.29%
92.9th percentile
Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat>= 10.1.0 < 10.1.3110.1.31
apachetomcat>= 9.0.0 < 9.0.969.0.96
apache_software_foundationapache_tomcat10.1.0-M1 – 10.1.30
apache_software_foundationapache_tomcat11.0.0-M1 – 11.0.0-M26
apache_software_foundationapache_tomcat8.5.0 – 8.5.100
apache_software_foundationapache_tomcat9.0.0-M1 – 9.0.95
debiandebian_linux
debiantomcat10< tomcat10 10.1.34-0+deb12u1 (bookworm)tomcat10 10.1.34-0+deb12u1 (bookworm)
debiantomcat9< tomcat10 10.1.34-0+deb12u1 (bookworm)tomcat10 10.1.34-0+deb12u1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Authentication bypass occurs when a custom Jakarta Authentication (JASPIC) ServerAuthContext component throws an exception during authentication without explicitly setting an HTTP status to indicate failure — monitor for unexpected successful authentication responses (HTTP 200/302) following exception conditions in Tomcat auth logs
  • Scope of exploitation is limited to Tomcat instances explicitly configured with a custom Jakarta Authentication ServerAuthContext — detection should focus on identifying such configurations in server.xml or application deployment descriptors
  • Exploitation requires a custom ServerAuthContext component that mishandles exceptions — audit deployed JASPIC/Jakarta Authentication modules for improper exception handling that does not set HTTP failure status codes
  • ·Vulnerability only affects Tomcat instances explicitly configured to use a custom Jakarta Authentication (JASPIC) ServerAuthContext component; default Tomcat configurations are not affected
  • ·Affected versions span Apache Tomcat 9.0.0-M1 through 9.0.95, 10.1.0-M1 through 10.1.30, 11.0.0-M1 through 11.0.0-M26, and EOL branch 8.5.0 through 8.5.100; fixed in 9.0.96, 10.1.31, and 11.0.0
  • ·Red Hat assesses Attack Complexity as High due to the multiple unlikely preconditions required for exploitation, rating all affected Red Hat products as Low severity despite a worst-case Important base flaw rating

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.