Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-29885

Опубликовано: 10 мая 2022
Источник: redhat
CVSS3: 3.7
EPSS Средний

Описание

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

Отчет

This flaw describes a mistake made in the documentation which overstated the protection provided by the clustering feature. As the impact is Low and a patch would not directly improve the security posture of Apache Tomcat, this flaw is marked as will not fix for all Red Hat products. This may be fixed in a future release.

Меры по смягчению последствий

For customers who use clustering on an untrusted network and require full protection, an alternate solution is recommended such as using a VPN.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7tomcatWill not fix
Red Hat Enterprise Linux 6tomcat6Will not fix
Red Hat Enterprise Linux 7tomcatWill not fix
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineWill not fix
Red Hat Enterprise Linux 9pki-servlet-engineWill not fix
Red Hat Fuse 7tomcatWill not fix
Red Hat JBoss Data Grid 6jbosswebWill not fix
Red Hat JBoss Data Virtualization 6jbosswebWill not fix
Red Hat JBoss Enterprise Application Platform 6jbosswebWill not fix
Red Hat JBoss Fuse 6tomcatWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1112
https://bugzilla.redhat.com/show_bug.cgi?id=2093014tomcat: EncryptInterceptor documentation mistake

EPSS

Процентиль: 98%
0.66148
Средний

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

CVSS3: 7.5
nvd
около 3 лет назад

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protect against all risks associated with running over any untrusted network, particularly DoS risks.

CVSS3: 7.5
debian
около 3 лет назад

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 ...

CVSS3: 7.5
github
около 3 лет назад

Apache Tomcat EncryptInterceptor error leads to Uncontrolled Resource Consumption

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость реализации класса EncryptInterceptor сервера приложений Apache Tomcat, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.66148
Средний

3.7 Low

CVSS3