CVE-2023-45648. tomcat-embed-core HTTP request smuggling - Analysis of vulnerability

Description

Severity: Medium
Link: https://nvd.nist.gov/vuln/detail/CVE-2023-45648
Package Name: tomcat-embed-core
Current 10.1.13 // fixed in 10.1.14, 9.0.81, 8.5.94

Modules impacted:
mod-password-validator Volaris
mod-tags Volaris
mod-calendar Bama
mod-notes Spitfire
edge-caiasoft Volaris – ,
mod-data-export-spring Firebird
mod-ebsconet Thunderjet
mod-data-export-worker Firebird
mod-bulk-operations Firebird
mod-fqm-manager Corsair
mod-lists Corsair
edge-courses Dreamliner –

Checklist

hide

TestRail: Results

Activity

Show:

Julian LadischOctober 9, 2024 at 12:02 PM

All back-ports have been released.

Julian LadischOctober 1, 2024 at 9:57 PM

I’ve requested CSP approval in #release_bug_triage Slack channel on September 19th.

Craig McNallyAugust 29, 2024 at 3:24 PM

Looks like it still hasn’t been released and therefore hasn’t been included in a Poppy CSP.

Julian LadischJuly 18, 2024 at 3:06 PM

The Poppy CSP backport for edge-caiasoft 2.1.1 hasn’t been released and therefore hasn’t been released as Poppy CSP: https://github.com/folio-org/platform-complete/blob/R2-2023-csp-6/install.json#L344

Craig McNallyJanuary 25, 2024 at 4:08 PM

Will close this once we verify that the fix for   has made it into Poppy CSP1

Done

Details

Assignee

Reporter

Priority

RCA Group

TBD

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created January 22, 2024 at 6:09 PM
Updated October 10, 2024 at 3:13 PM
Resolved October 10, 2024 at 3:07 PM
TestRail: Cases
TestRail: Runs