Impact
The vulnerability allows a WebSocket session established under an authenticated HTTP session to remain active after the HTTP session ends. This flaw enables an attacker to maintain a privileged connection or reuse the session credentials after logout, resulting in session hijacking or unauthorized access. The weakness is a session‑management flaw classified as CWE-613.
Affected Systems
Affected versions are Apache Tomcat 9.0.0.M1 through 9.0.120, 10.1.0-M1 through 10.1.57, and 11.0.0-M1 through 11.0.24. Older supported releases 8.5.0 through 8.5.100 and 7.0.43 through 7.0.109 are also known to be vulnerable, though these are End‑of‑Life.
Risk and Exploitability
The EPSS score is 0.00276, corresponding to a 0.28% probability of exploitation, the vulnerability is not listed in CISA KEV, and the CVSS score is 6.8. The exploit requires a user to be authenticated and to establish or modify a WebSocket bound to that session before changing the session ID. Although the path is not trivial, the potential for ongoing unauthorized access makes it a medium‑to‑high risk for applications that rely on WebSockets for critical functionality. Administrators should act promptly to apply the available fixes.
OpenCVE Enrichment