Skip to main content

Improper Check for Unusual or Exceptional Conditions in org.apache.tomcat.embed:tomcat-embed-core

CVE-2024-52316

  • org.apache.tomcat.embed:tomcat-embed-core
  • org.apache.tomcat.experimental:tomcat-embed-programmatic
  • org.apache.tomcat:tomcat-catalina
Severity High
Score 9.8/10

Summary

Unchecked Error Condition vulnerability in Apache Tomcat versions 9.0.0-M1 through 9.0.95, 10.1.0-M1 through 10.1.30, and 11.0.0-M1 through 11.0.0-M26. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) "ServerAuthContext" component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-754 - Improper Check for Unusual or Exceptional Conditions

The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.

Advisory Timeline

  • Published