CVE-2023-41080

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:11.0.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone4:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone7:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone8:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone9:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone10:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone6:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

07 Aug 2025, 11:15

Type Values Removed Values Added
References (MISC) https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f - Issue Tracking, Patch, Vendor Advisory () https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f - Issue Tracking, Patch, Vendor Advisory
References (MISC) https://www.debian.org/security/2023/dsa-5521 - Third Party Advisory () https://www.debian.org/security/2023/dsa-5521 - Third Party Advisory
References (MISC) https://security.netapp.com/advisory/ntap-20230921-0006/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20230921-0006/ - Third Party Advisory
References (MISC) https://www.debian.org/security/2023/dsa-5522 - Third Party Advisory () https://www.debian.org/security/2023/dsa-5522 - Third Party Advisory
References (MISC) https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html - Mailing List, Third Party Advisory
Summary URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. The vulnerability is limited to the ROOT (default) web application. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.
CWE CWE-601

03 Nov 2023, 19:00

Type Values Removed Values Added
References (MISC) https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html - (MISC) https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html - Mailing List, Third Party Advisory
References (MISC) https://security.netapp.com/advisory/ntap-20230921-0006/ - (MISC) https://security.netapp.com/advisory/ntap-20230921-0006/ - Third Party Advisory
References (MISC) https://www.debian.org/security/2023/dsa-5521 - (MISC) https://www.debian.org/security/2023/dsa-5521 - Third Party Advisory
References (MISC) https://www.debian.org/security/2023/dsa-5522 - (MISC) https://www.debian.org/security/2023/dsa-5522 - Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
First Time Debian
Debian debian Linux

13 Oct 2023, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References
  • (MISC) https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html -
  • (MISC) https://security.netapp.com/advisory/ntap-20230921-0006/ -
  • (MISC) https://www.debian.org/security/2023/dsa-5521 -
  • (MISC) https://www.debian.org/security/2023/dsa-5522 -
References (MISC) https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f - (MISC) https://lists.apache.org/thread/71wvwprtx2j2m54fovq9zr7gbm2wow2f - Issue Tracking, Patch, Vendor Advisory
CPE cpe:2.3:a:apache:tomcat:11.0.0:milestone4:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone6:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone9:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone8:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone10:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone7:*:*:*:*:*:*
First Time Apache
Apache tomcat

25 Aug 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-25 21:15

Updated : 2025-08-07 11:15


NVD link : CVE-2023-41080

Mitre link : CVE-2023-41080


JSON object : View

Products Affected

debian

  • debian_linux

apache

  • tomcat
CWE

No CWE.