CVE-2013-2067
Publication date 10 May 2013
Last updated 24 July 2024
Ubuntu priority
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
tomcat6 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
tomcat7 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Patch details
Package | Patch details |
---|---|
tomcat6 | |
tomcat7 |
References
Related Ubuntu Security Notices (USN)
- USN-1841-1
- Tomcat vulnerabilities
- 28 May 2013