Re: Clarification on CVE-2023-46589

2023-12-14 Thread Benny Prange
Am Do., 14. Dez. 2023 um 16:51 Uhr schrieb Mark Thomas : > On 14/12/2023 15:33, Benny Prange wrote: > > Hi all, > > > > I am having trouble understanding the description of CVE-2023-46589. > > Does this CVE affect scenarios where the Apache Tomcat is the reverse >

Clarification on CVE-2023-46589

2023-12-14 Thread Benny Prange
Hi all, I am having trouble understanding the description of CVE-2023-46589. Does this CVE affect scenarios where the Apache Tomcat is the reverse proxy, or or when the Apache Tomcat is running behind a reverse proxy? Is the Tomcat vulnerable to request smuggling, or other applications running beh