Executive brief
Apache Tomcat, a widely used web server for Java applications, contains a vulnerability in its FORM authentication feature. An attacker could trick a user into visiting a malicious link that redirects them from a legitimate site to a fraudulent one, potentially leading to phishing or credential theft. This issue specifically impacts the default ROOT web application.
Technical details
An open redirect vulnerability (CWE-601) exists in the FORM authentication component of Apache Tomcat. The flaw is located within the ROOT (default) web application and allows an attacker to supply a user-controlled input that the application uses as a redirect target without proper validation. By enticing a user to click a specially crafted URL, a remote attacker can redirect the victim to an arbitrary external domain. This can be leveraged in phishing campaigns to steal credentials or distribute malware. The issue is resolved in versions 8.5.93, 9.0.80, 10.1.13, and 11.0.0-M11.
Affected products
- Apache Tomcat 8.5.0 to 8.5.92, 9.0.0-M1 to 9.0.79, 10.1.0-M1 to 10.1.12, 11.0.0-M1 to 11.0.0-M10
Timeline
- 2023-08-25: disclosed
- 2023-08-25: advisory