Session Fixation In org.apache.tomcat.embed:tomcat-embed-core
Description
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 9.0.31-1 | ||
maven | 7.0.99, 8.5.50, 9.0.30 | ||
debian 11 | 9.0.31-1 | ||
debian 13 | 9.0.31-1 | ||
debian 14 | 9.0.31-1 | ||
maven | 7.0.99, 8.5.50, 9.0.30 | ||
rpm rhel8 | - | - | |
rpm rhel7 | 0:7.0.76-15.el7 | ||
rpm rhel7.6 | 0:7.0.76-11.el7_6 | ||
rpm rhel7.7 | 0:7.0.76-12.el7_7 |
1-10 of 12
10
Aliases
References