PT-2023-8633 · Apache+11 · Apache Tomcat+13

·

CVE-2023-46589

·

Published

2023-11-13

·

Updated

2026-08-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.0-M10 Apache Tomcat versions 10.1.0-M1 through 10.1.15 Apache Tomcat versions 9.0.0-M1 through 9.0.82 Apache Tomcat versions 8.5.0 through 8.5.95
Description The issue is related to an Improper Input Validation vulnerability in Apache Tomcat, where Tomcat does not correctly parse HTTP trailer headers. If a trailer header exceeds the header size limit, Tomcat may treat a single request as multiple requests, leading to the possibility of request smuggling when behind a reverse proxy.
Recommendations To resolve the issue, upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards, or 8.5.96 onwards, which fix the issue. For Bitbucket Data Center and Server, upgrade to a release greater than or equal to 7.21.21, 8.9.9, 8.13.5, 8.14.4, 8.15.3, or 8.16.2. For Bamboo Data Center and Server, upgrade to a release greater than or equal to 9.2.8, 9.3.6, or 9.4.2. As a temporary workaround, consider restricting access to the vulnerable module to minimize the risk of exploitation.

Exploit

Fix

DoS

HTTP Request/Response Smuggling

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0539
ALSA-2024:1134
ALT-PU-2023-8058
ALT-PU-2024-4687
ALT-PU-2024-4975
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2024-01300
BIT-TOMCAT-2023-46589
CESA-2024_0539
CVE-2023-46589
DLA-3707-1
DSA-5665-1
DSA-5667-1
GHSA-FCCV-JMMP-QG76
OESA-2024-2402
OESA-2024-2403
OESA-2024-2404
OESA-2024-2405
OESA-2024-2460
OPENSUSE-SU-2024:13590-1
OPENSUSE-SU-2024:13596-1
OPENSUSE-SU-2024_0208-1
OPENSUSE-SU-2024_0472-1
RHSA-2024:0532
RHSA-2024:0539
RHSA-2024:1092
RHSA-2024:1134
RHSA-2024:1318
RHSA-2024:1324
RHSA-2024_0539
RHSA-2024_1134
RLSA-2024:0539
ROSA-SA-2024-2544
SUSE-SU-2024:0206-1
SUSE-SU-2024:0208-1
SUSE-SU-2024:0209-1
SUSE-SU-2024:0472-1
SUSE-SU-2024_0206-1
SUSE-SU-2024_0208-1
SUSE-SU-2024_0209-1
SUSE-SU-2026:1058-1
USN-7032-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Astra Linux
Bamboo
Bitbucket
Centos
Confluence
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu