The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1400-1 | tomcat7 security update |
Debian DSA |
DSA-3974-1 | tomcat8 security update |
EUVD |
EUVD-2022-2904 | The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances. |
Github GHSA |
GHSA-73rx-3f9r-x949 | Insufficient Verification of Data Authenticity in Apache Tomcat |
Ubuntu USN |
USN-3519-1 | Tomcat vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T03:47:49.467Z
Reserved: 2017-04-11T00:00:00
Link: CVE-2017-7674
No data.
Status : Deferred
Published: 2017-08-11T02:29:00.287
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7674
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN