Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade RHEL:9 tomcat-lib to version 1:9.0.62-37.el9_3.1 or higher.
This issue was patched in RHSA-2024:0474.
Note: Versions mentioned in the description apply only to the upstream tomcat-lib package and not the tomcat-lib package as distributed by RHEL.
See How to fix? for RHEL:9 relevant fixed versions and status.
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected.
The vulnerability is limited to the ROOT (default) web application.