Back

LOW

tomcat: information disclosure in authentication headers

Published Apr 23, 2010

Description

Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.

Affected products

Remediation

Red Hat statement

The risks associated with fixing this flaw are greater than the low severity security risk. We therefore have no plans to fix this flaw. The information leak can be avoided by adjusting the configuration to always specify a realm-name.

References (54)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 23, 2010
Updated Aug 7, 2024
Reserved Mar 29, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 21, 2010
ENISA EUVD
Assigner redhat
Published Apr 23, 2010
Updated Aug 7, 2024
Exploited since n/a
EUVD-2022-5514 GHSA-W6Q7-WW2X-7GM3