CVE-2018-8014
Published: 16 May 2018
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Priority
Status
Package | Release | Status |
---|---|---|
tomcat7 Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(7.0.78-1)
|
bionic |
Not vulnerable
|
|
cosmic |
Not vulnerable
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
trusty |
Released
(7.0.52-1ubuntu0.14)
|
|
upstream |
Released
(7.0.72-3)
|
|
xenial |
Needed
|
|
Patches: upstream: https://svn.apache.org/r1831730 |
||
tomcat8 Launchpad, Ubuntu, Debian |
artful |
Released
(8.5.21-1ubuntu1.1)
|
bionic |
Released
(8.5.30-1ubuntu1.2)
|
|
cosmic |
Released
(8.5.30-1ubuntu3)
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(8.0.53,8.5.32)
|
|
xenial |
Released
(8.0.32-1ubuntu1.6)
|
|
Patches: upstream: https://svn.apache.org/r1831728 upstream: https://svn.apache.org/r1831729 |
||
tomcat8.0 Launchpad, Ubuntu, Debian |
artful |
Ignored
(end of life)
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Released
(8.0.53)
|
|
xenial |
Does not exist
|
|
Patches: upstream: https://svn.apache.org/r1831728 upstream: https://svn.apache.org/r1831729 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
- http://tomcat.apache.org/security-7.html
- http://tomcat.apache.org/security-8.html
- http://tomcat.apache.org/security-9.html
- https://lists.apache.org/thread.html/fbfb713e4f8a4c0f81089b89450828011343593800cae3fb629192b1@%3Cannounce.tomcat.apache.org%3E
- https://ubuntu.com/security/notices/USN-3665-1
- https://www.cve.org/CVERecord?id=CVE-2018-8014
- NVD
- Launchpad
- Debian