PT-2018-2141 · Apache+7 · Apache Tomcat+7

Published

2018-05-16

·

Updated

2025-09-15

·

CVE-2018-8014

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.8 Apache Tomcat versions 8.5.0 through 8.5.31 Apache Tomcat versions 8.0.0.RC1 through 8.0.52 Apache Tomcat versions 7.0.41 through 7.0.88
Description The issue is related to insufficient access control in the CORS component of the Apache Tomcat servlet container. This could allow a remote attacker to gain unauthorized access to protected data using the HTTP protocol. The default settings for the CORS filter are insecure, enabling supportsCredentials for all origins. However, it is expected that most users will not be impacted as they would have configured the filter according to their environment.
Recommendations For Apache Tomcat versions 9.0.0.M1 through 9.0.8, consider configuring the CORS filter to restrict supportsCredentials to specific origins. For Apache Tomcat versions 8.5.0 through 8.5.31, configure the CORS filter to limit supportsCredentials to necessary domains. For Apache Tomcat versions 8.0.0.RC1 through 8.0.52, adjust the CORS filter settings to securely manage supportsCredentials. For Apache Tomcat versions 7.0.41 through 7.0.88, update the CORS filter configuration to properly restrict supportsCredentials for all origins.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:1529
ALT-PU-2019-1516
BDU:2019-00094
CESA-2019_1529
CESA-2019_2205
CVE-2018-8014
DLA-1400-1
DLA-1400-2
DLA-1883-1
DSA-4596-1
GHSA-R4X2-3CQ5-HQVP
MGASA-2018-0479
OPENSUSE-SU-2018_2740-1
OPENSUSE-SU-2018_3054-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2018:2469
RHSA-2019:0451
RHSA-2019:1529
RHSA-2019:2205
RHSA-2019_1529
RHSA-2019_2205
RLSA-2019:1529
SUSE-SU-2018:2699-1
SUSE-SU-2018:3011-1
SUSE-SU-2018:3261-1
SUSE-SU-2018:3388-1
USN-3665-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Centos
Red Hat
Rocky Linux
Suse
Ubuntu