Apache Tomcat: Authentication bypass when using Jakarta Authentication API (CVE-2024-52316)
Apache Tomcat contains an authentication bypass vulnerability when using a custom Jakarta Authentication API ServerAuthContext component that throws an exception without setting an HTTP failure status. This may allow authentication to succeed improperly. No known Jakarta Authentication components currently behave this way. The issue affects multiple Tomcat versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.0. Fixed versions are 11.0.0, 10.1.31, and 9.0.96. Users should upgrade to these versions to remediate the vulnerability.
AI Analysis
Technical Summary
CVE-2024-52316 is an unchecked error condition vulnerability in Apache Tomcat's handling of authentication when configured with a custom Jakarta Authentication ServerAuthContext component. If such a component throws an exception during authentication without explicitly setting an HTTP failure status, the authentication process may not fail as intended, resulting in an authentication bypass. Although no known Jakarta Authentication components currently exhibit this behavior, the vulnerability affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.95, 10.1.0 through 10.1.30, and 11.0.0. The issue is fixed in versions 9.0.96, 10.1.31, and 11.0.0.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication controls if a custom Jakarta Authentication ServerAuthContext component throws an exception without setting an HTTP failure status. This could lead to unauthorized access to applications hosted on affected Apache Tomcat servers. However, no known Jakarta Authentication components currently behave in this vulnerable manner, which may limit the practical impact.
Mitigation Recommendations
A patch is available. Users are recommended to upgrade Apache Tomcat to versions 11.0.0, 10.1.31, or 9.0.96 or later, which include fixes for this vulnerability. Applying these official updates will remediate the authentication bypass issue. No other specific mitigations are indicated by the vendor advisory.
Apache Tomcat: Authentication bypass when using Jakarta Authentication API (CVE-2024-52316)
Description
Apache Tomcat contains an authentication bypass vulnerability when using a custom Jakarta Authentication API ServerAuthContext component that throws an exception without setting an HTTP failure status. This may allow authentication to succeed improperly. No known Jakarta Authentication components currently behave this way. The issue affects multiple Tomcat versions including 8.5.x, 9.0.x, 10.1.x, and 11.0.0. Fixed versions are 11.0.0, 10.1.31, and 9.0.96. Users should upgrade to these versions to remediate the vulnerability.
Affected software
pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm3?arch=source&distro=esm-apps/nobleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2024-52316 is an unchecked error condition vulnerability in Apache Tomcat's handling of authentication when configured with a custom Jakarta Authentication ServerAuthContext component. If such a component throws an exception during authentication without explicitly setting an HTTP failure status, the authentication process may not fail as intended, resulting in an authentication bypass. Although no known Jakarta Authentication components currently exhibit this behavior, the vulnerability affects Apache Tomcat versions from 8.5.0 through 8.5.100, 9.0.0 through 9.0.95, 10.1.0 through 10.1.30, and 11.0.0. The issue is fixed in versions 9.0.96, 10.1.31, and 11.0.0.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication controls if a custom Jakarta Authentication ServerAuthContext component throws an exception without setting an HTTP failure status. This could lead to unauthorized access to applications hosted on affected Apache Tomcat servers. However, no known Jakarta Authentication components currently behave in this vulnerable manner, which may limit the practical impact.
Mitigation Recommendations
A patch is available. Users are recommended to upgrade Apache Tomcat to versions 11.0.0, 10.1.31, or 9.0.96 or later, which include fixes for this vulnerability. Applying these official updates will remediate the authentication bypass issue. No other specific mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2024-52316
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50e68715ace43db325f
Added to database: 07/16/2026, 10:40:14 UTC
Last enriched: 09/08/2026, 15:09:25 UTC
Last updated: 09/10/2026, 19:36:48 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.