Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-28708
Description:When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2023.1672.1   1.3.6.1.4.1.25623.1.0.104654   1.3.6.1.4.1.25623.1.0.104653   1.3.6.1.4.1.25623.1.1.1.1.2023.5381   1.3.6.1.4.1.25623.1.1.1.2.2023.3384   1.3.6.1.4.1.25623.1.1.4.2023.1669.1  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-28708
https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67
https://lists.apache.org/thread/hdksc59z3s7tm39x0pp33mtwdrt8qr67




© 1998-2025 E-Soft Inc. All rights reserved.