Vulnerability Database

289,598

Total vulnerabilities in the database

CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92.

The vulnerability is limited to the ROOT (default) web application.

CVSS v3:

  • Severity: Medium
  • Score: 6.1
  • AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CWEs:

Software From Fixed in
org.apache.tomcat / tomcat 11.0.0-M1 11.0.0-M11
org.apache.tomcat / tomcat 10.1.0-M1 10.1.13
org.apache.tomcat / tomcat 9.0.0-M1 9.0.80
org.apache.tomcat / tomcat 8.5.0 8.5.93
apache / tomcat 11.0.0-milestone1 11.0.0-milestone1.x
apache / tomcat 11.0.0-milestone2 11.0.0-milestone2.x
apache / tomcat 11.0.0-milestone4 11.0.0-milestone4.x
apache / tomcat 11.0.0-milestone3 11.0.0-milestone3.x
apache / tomcat 11.0.0-milestone5 11.0.0-milestone5.x
apache / tomcat 11.0.0-milestone7 11.0.0-milestone7.x
apache / tomcat 11.0.0-milestone8 11.0.0-milestone8.x
apache / tomcat 11.0.0-milestone9 11.0.0-milestone9.x
apache / tomcat 11.0.0-milestone10 11.0.0-milestone10.x
apache / tomcat 10.1.0 10.1.12.x
apache / tomcat 8.5.0 8.5.92.x
apache / tomcat 9.0.0 9.0.79.x
apache / tomcat 11.0.0-milestone6 11.0.0-milestone6.x
org.apache.tomcat.embed / tomcat-embed-core 8.5.0 8.5.93
org.apache.tomcat.embed / tomcat-embed-core 9.0.0-M1 9.0.80
org.apache.tomcat.embed / tomcat-embed-core 10.1.0-M1 10.1.13
org.apache.tomcat.embed / tomcat-embed-core 11.0.0-M1 11.0.0-M11
debian / debian_linux 10.0 10.0.x
debian / debian_linux 11.0 11.0.x