← Back

CVE-2023-28708

nvd nist
Published: Mar 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.

Affected (5)

Products: Apache: Tomcat
1 product
Tomcat
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Apache
After 10.1.0 to 10.1.6
After 9.0.0 to 9.0.72
From 8.5.0 to 8.5.86
Version 11.0.0 milestone1
Version 11.0.0 milestone2

References (3)

Source: security@apache.org
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.