Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-45648


Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.


Published

2023-10-10T19:15:09.690

Last Modified

2025-06-16T17:15:27.480

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Secondary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat < 8.5.94 Yes
Application apache tomcat < 9.0.81 Yes
Application apache tomcat < 10.1.14 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 9.0.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 10.1.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System debian debian_linux 12.0 Yes

References