The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DLA-1400-1 | tomcat7 security update |
![]() |
DLA-1883-1 | tomcat8 security update |
![]() |
DSA-4596-1 | tomcat8 security update |
![]() |
GHSA-r4x2-3cq5-hqvp | The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins |
![]() |
USN-3665-1 | Tomcat vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T06:46:11.468Z
Reserved: 2018-03-09T00:00:00
Link: CVE-2018-8014

No data.

Status : Modified
Published: 2018-05-16T16:29:00.207
Modified: 2024-11-21T04:13:05.810
Link: CVE-2018-8014


No data.