When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
History

Thu, 13 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-02-13T14:36:47.576Z

Reserved: 2023-03-21T17:26:28.837Z

Link: CVE-2023-28708

cve-icon Vulnrichment

Updated: 2024-08-02T13:43:23.678Z

cve-icon NVD

Status : Modified

Published: 2023-03-22T11:15:10.623

Modified: 2025-02-13T15:15:16.783

Link: CVE-2023-28708

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-03-22T00:00:00Z

Links: CVE-2023-28708 - Bugzilla