Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat
ID: 4cde6080-7166-58b9-97c1-3d6217f3b5c2
STIX ID: report--4cde6080-7166-58b9-97c1-3d6217f3b5c2
Feed Name: securityonline.info
Threat Score
Apache Tomcat has ten disclosed vulnerabilities across multiple branches (8.5, 9.0, 10.1, 11.0) that include high-impact cryptographic issues (a padding oracle and an EncryptInterceptor bypass), OCSP/client-cert soft-fail logic, exposure of Kubernetes bearer tokens in logs, HTTP request smuggling, open redirect, and JSON logging escape; administrators are advised to upgrade immediately (and update Tomcat Native) to remediate these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
