PT-2018-2767 · Apache+5 · Apache Tomcat+5

Published

2018-02-11

·

Updated

2025-09-29

·

CVE-2018-1304

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 9.0.0.M1 through 9.0.4 Apache Tomcat versions 8.5.0 through 8.5.27 Apache Tomcat versions 8.0.0.RC1 through 8.0.49 Apache Tomcat versions 7.0.0 through 7.0.84
Description The issue arises from the incorrect handling of the URL pattern "" (the empty string) that exactly maps to the context root when used as part of a security constraint definition. This causes the constraint to be ignored, allowing unauthorized users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string are affected.
Recommendations For Apache Tomcat versions 9.0.0.M1 through 9.0.4, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 8.5.0 through 8.5.27, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 8.0.0.RC1 through 8.0.49, update to a version outside of this range to resolve the issue. For Apache Tomcat versions 7.0.0 through 7.0.84, update to a version outside of this range to resolve the issue. As a temporary workaround, consider reviewing and adjusting security constraint definitions to avoid the use of the empty string URL pattern.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2018-1731
BDU:2019-01759
CESA-2019_2205
CVE-2018-1304
DLA-1301-1
DLA-1400-1
DLA-1400-2
DLA-1450-1
DSA-4281-1
ELSA-2019-2205
GHSA-6RXJ-58JH-436R
MGASA-2018-0149
RHSA-2018:0466
RHSA-2018:1448
RHSA-2018:1449
RHSA-2018:1450
RHSA-2018:1451
RHSA-2019:2205
RHSA-2019_2205
SUSE-SU-2018:0817-1
SUSE-SU-2018:1847-1
SUSE-SU-2018:3261-1
SUSE-SU-2018:3388-1
SUSE-SU-2018_1847-1
USN-3665-1

Affected Products

Alt Linux
Apache Tomcat
Centos
Red Hat
Suse
Ubuntu