Junglewise Threat Intelligence

CVE-2023-41080: Apache Tomcat open redirect in FORM authentication

CVE-2023-41080 · Severity: medium · CVSS 6.1 · Published 2023-08-25

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely used web server for Java applications, contains a vulnerability in its FORM authentication feature. An attacker could trick a user into visiting a malicious link that redirects them from a legitimate site to a fraudulent one, potentially leading to phishing or credential theft. This issue specifically impacts the default ROOT web application.

Technical details

An open redirect vulnerability (CWE-601) exists in the FORM authentication component of Apache Tomcat. The flaw is located within the ROOT (default) web application and allows an attacker to supply a user-controlled input that the application uses as a redirect target without proper validation. By enticing a user to click a specially crafted URL, a remote attacker can redirect the victim to an arbitrary external domain. This can be leveraged in phishing campaigns to steal credentials or distribute malware. The issue is resolved in versions 8.5.93, 9.0.80, 10.1.13, and 11.0.0-M11.

Affected products

  • Apache Tomcat 8.5.0 to 8.5.92, 9.0.0-M1 to 9.0.79, 10.1.0-M1 to 10.1.12, 11.0.0-M1 to 11.0.0-M10

Timeline

  • 2023-08-25: disclosed
  • 2023-08-25: advisory

References

Related threats