VDB
Sign up
MEDIUM6.5

GHSA-24j9-x2wg-9qv6

Apache Tomcat: CLIENT_CERT authentication does not fail as expected

Quick fix

GHSA-24j9-x2wg-9qv6 — org.apache.tomcat:tomcat-coyote-ffm: upgrade to the fixed version with the command below.

# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-coyote-ffm

Details

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in: 9.0.92Fixed in: 9.0.117
Fix# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-coyote-ffm
Maven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in: 10.1.22Fixed in: 10.1.54
Fix# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-coyote-ffm
Maven/org.apache.tomcat:tomcat-coyote-ffm
Introduced in: 11.0.0-M14Fixed in: 11.0.21
Fix# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-coyote-ffm

References