Apache Security Updates – 29 November 2023

ache has released security updates to address several vulnerabilities in Apache Tomcat versions prior to 9.0.83.

The addressed vulnerabilities could allow the remote attacker to obtain sensitive information, conduct denial of service attacks, bypass web application firewall protection, conduct XSS attacks, and gain access to the affected system by sending
a specially crafted HTTP(S) trailer header.

Sample of the addressed vulnerabilities:

Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2023-46589):

  • CVSS: 6.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2023-46589
  • CVE-2023-45648
  • CVE-2023-42795
  • CVE-2023-42794
Mitigations

The enterprise should deploy the patches as soon as the testing phase is completed.

Apache Tomcat Security Updates

References