AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-28708

MEDIUM · CVSS 4.3 EPSS 1.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-03-22 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-28708
Severity
MEDIUM
CVSS
4.3
EPSS
1.83%
Apache

Original NVD Description

When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel. Older, EOL versions may also be affected.