CVE-2023-45648 Details
Description
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp | CVE | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html | CVE | Mailing ListThird Party Advisory |
| https://security.netapp.com/advisory/ntap-20231103-0007/ | CVE | |
| https://www.debian.org/security/2023/dsa-5521 | CVE | Third Party Advisory |
| https://www.debian.org/security/2023/dsa-5522 | CVE | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2023/10/10/10 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdp | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 8.5.0, < 8.5.94 >= 9.0.1, < 9.0.81 >= 10.1.1, < 10.1.14 9.0.0 milestone1 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone19 9.0.0 milestone2 9.0.0 milestone20 9.0.0 milestone21 9.0.0 milestone22 9.0.0 milestone23 9.0.0 milestone24 9.0.0 milestone25 9.0.0 milestone26 9.0.0 milestone27 9.0.0 milestone3 9.0.0 milestone4 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 10.1.0 milestone1 10.1.0 milestone10 10.1.0 milestone11 10.1.0 milestone12 10.1.0 milestone13 10.1.0 milestone14 10.1.0 milestone15 10.1.0 milestone16 10.1.0 milestone17 10.1.0 milestone18 10.1.0 milestone19 10.1.0 milestone2 10.1.0 milestone20 10.1.0 milestone3 10.1.0 milestone4 10.1.0 milestone5 10.1.0 milestone6 10.1.0 milestone7 10.1.0 milestone8 10.1.0 milestone9 11.0.0 milestone1 11.0.0 milestone10 11.0.0 milestone11 11.0.0 milestone2 11.0.0 milestone3 11.0.0 milestone4 11.0.0 milestone5 11.0.0 milestone6 11.0.0 milestone7 11.0.0 milestone8 11.0.0 milestone9 |
CPE
Remediation
| |
| debian debian linux | 10.0 11.0 12.0 |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Aug 7, 2025 | CVE Modified | [email protected] |
| Jun 16, 2025 | CVE Modified | CISA-ADP |
| Feb 13, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 4, 2023 | CVE Modified | [email protected] |
| Oct 16, 2023 | Initial Analysis | [email protected] |
| Oct 13, 2023 | CVE Modified | [email protected] |
| Oct 11, 2023 | CVE Modified | [email protected] |
| Oct 10, 2023 | CVE Modified | [email protected] |