Skip to content

[FALSE-POSITIVE] CVE-2023-45648 #15432

@cepakj

Description

@cepakj

Template IDs or paths

**Template affected:**  
`http/cves/2023/CVE-2023-45648.yaml`
 
The passive version detection regex in the template incorrectly flags Apache Tomcat versions **10.1.14 and higher** (including the current latest 10.1.52) as vulnerable to **CVE-2023-45648**.

Environment

- OS: 
- Nuclei: 
- Go:

Steps To Reproduce

Run nuclei against any server running Tomcat 10.1.14 – 10.1.52 (e.g. visible in default 404 page: Apache Tomcat/10.1.52 (Debian)).

Relevant dumped responses

Anything else?

No response

Metadata

Metadata

Assignees

Labels

false-positiveNuclei template reporting invalid/unexpected result

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions