Impact
An authentication bypass flaw allows an attacker to circumvent the security constraints applied to WebSocket endpoints in Apache Tomcat. The vulnerability permits the use of alternate names to reach protected endpoints, effectively granting unauthorized access and the ability to read, modify, or inject traffic through the WebSocket channel.
Affected Systems
Apache Tomcat, versions 7.0.43 to 7.0.109, 8.5.0 to 8.5.100, 9.0.0.M1 to 9.0.121, 10.1.0-M1 to 10.1.59, and 11.0.0-M1 to 11.0.25 are affected. The End‑of‑Support releases 8.5.0–8.5.100 and 7.0.43–7.0.109 are also known to be vulnerable.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV catalog, but the nature of the flaw—an authentication bypass—suggests a high impact if exploited. Attackers could use the WebSocket handshake to gain unauthorized access without credentials. Without a CVSS score, the severity cannot be precisely quantified, but the combination of an authentication bypass and WebSocket exposure indicates a significant risk of confidentiality and integrity compromise.
OpenCVE Enrichment