Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-1305

Опубликовано: 23 фев. 2018
Источник: debian
EPSS Низкий

Описание

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tomcat9not-affectedpackage
tomcat8fixed8.5.28-1package
tomcat8.0removedpackage
tomcat7fixed7.0.72-3package

Примечания

  • tomcat8.0 builds only tomcat8.0-user and libtomcat8.0-java

  • Since 7.0.72-3, src:tomcat7 only builds the Servlet API

  • https://svn.apache.org/r1823314 (8.5.x)

  • https://svn.apache.org/r1824358 (8.5.x)

  • https://svn.apache.org/r1823319 (8.0.x)

  • https://svn.apache.org/r1824359 (8.0.x)

  • https://svn.apache.org/r1823322 (7.0.x)

  • https://svn.apache.org/r1824360 (7.0.x)

EPSS

Процентиль: 92%
0.07914
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

CVSS3: 4.8
redhat
больше 7 лет назад

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

CVSS3: 6.5
nvd
больше 7 лет назад

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

CVSS3: 6.5
github
больше 6 лет назад

Apache Tomcat information exposure vulnerability

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками контроля доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 92%
0.07914
Низкий