SA-2023-037 - Apache Tomcat JSESSIONID Cookie (CVE-2023-28708)
Summary When RemoteIpFilter is used with requests received from a reverse proxy via HTTP with the X-Forwarded-Proto header set to https, some versions of Apache Tomcat did not include the secure attri...
