Search CVE reports


Toggle filters

81 – 82 of 82 results


CVE-2023-28709

Medium priority
Ignored

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that...

6 affected packages

tomcat6, tomcat7, tomcat9, tomcat10, tomcat11, tomcat8

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not in release Not affected
tomcat9 Not affected Not affected Not affected Not affected Not affected
tomcat10 Not affected Not affected Not in release Not in release Not in release
tomcat11 Not affected Not in release Not in release Not in release Not in release
tomcat8 Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2023-28708

Medium priority

Some fixes available 9 of 17

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to...

6 affected packages

tomcat6, tomcat7, tomcat8, tomcat9, tomcat10, tomcat11

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tomcat6 Not in release Not in release Not in release Not in release Not in release
tomcat7 Not in release Not in release Not in release Not in release Not affected
tomcat8 — — Not in release Not in release Fixed
tomcat9 Fixed Fixed Fixed Fixed Fixed
tomcat10 Not affected Not affected Not in release Not in release Not in release
tomcat11 Not affected Not in release Not in release Not in release Not in release
Show less packages