Description
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1400-1 | tomcat7 security update |
Debian DSA |
DSA-3974-1 | tomcat8 security update |
EUVD |
EUVD-2022-2904 | The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances. |
Github GHSA |
GHSA-73rx-3f9r-x949 | Insufficient Verification of Data Authenticity in Apache Tomcat |
Ubuntu USN |
USN-3519-1 | Tomcat vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T03:47:49.467Z
Reserved: 2017-04-11T00:00:00.000Z
Link: CVE-2017-7674
No data.
Status : Deferred
Published: 2017-08-11T02:29:00.287
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7674
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN