Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
| Vendor | Product | Versions |
|---|---|---|
| apache | tomcat | maven/org.apache.tomcat:tomcat: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat:tomcat: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat:tomcat: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat:tomcat: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat:tomcat: >= 7.0.30, <= 7.0.109, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 7.0.30, <= 7.0.109, maven/org.apache.tomcat:tomcat-catalina: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat:tomcat-catalina: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat:tomcat-catalina: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat:tomcat-catalina: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat:tomcat-catalina: >= 7.0.30, <= 7.0.109 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | tomcat | cert_advisory | 90% |
| maven | org.apache.tomcat:tomcat | GHSA | 85% |
| maven | org.apache.tomcat.embed:tomcat-embed-core | GHSA | 85% |
| maven | org.apache.tomcat:tomcat-catalina | GHSA | 85% |
Loading…