Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-52316


Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue.


Published

2024-11-18T12:15:18.600

Last Modified

2025-11-07T16:15:59.050

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-391
  • Type: Primary
    CWE-754

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache tomcat < 9.0.96 Yes
Application apache tomcat < 10.1.31 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Application apache tomcat 11.0.0 Yes
Operating System debian debian_linux 11.0 Yes

References