Improper Input Validation vulnerability in Apache Tomcat (CVE-2023-38545) could potentially lead to request smuggling.
book
Article ID: 100062729
calendar_today
Updated On:
Cause
Apache Tomcat source code issue.
Resolution
There are no plans to address this issue by way of a patch or hotfix in earlier versions of the software at the present time. However, the issue has been addressed in the revision of the product specified at the end of this article.
Please contact your Veritas Sales representative or the Veritas Sales group for upgrade information including upgrade eligibility to the release containing the resolution for this issue.
eDiscovery Platform version 10.2.5 addresses this vulnerability with an updated version of Apache Tomcat 9.0.83.
Issue/Introduction
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
Was this article helpful?
thumb_up
Yes
thumb_down
No