Description
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1301-1 | tomcat7 security update |
Debian DLA |
DLA-1400-1 | tomcat7 security update |
Debian DLA |
DLA-1450-1 | tomcat8 security update |
Debian DSA |
DSA-4281-1 | tomcat8 security update |
EUVD |
EUVD-2018-0522 | The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected. |
Github GHSA |
GHSA-6rxj-58jh-436r | Apache Tomcat unauthorized access vulnerability |
Ubuntu USN |
USN-3665-1 | Tomcat vulnerabilities |
References
History
No history.
Subscriptions
Apache
Subscribe
Tomcat
Subscribe
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Oracle
Subscribe
Fusion Middleware
Subscribe
Hospitality Guest Access
Subscribe
Micros Relate Crm Software
Subscribe
Secure Global Desktop
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Web Server
Subscribe
Jboss Fuse
Subscribe
Jboss Middleware
Subscribe
Openshift Application Runtimes
Subscribe
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T01:35:47.135Z
Reserved: 2017-12-07T00:00:00.000Z
Link: CVE-2018-1304
No data.
Status : Modified
Published: 2018-02-28T20:29:00.227
Modified: 2024-11-21T03:59:35.043
Link: CVE-2018-1304
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN