CVE-2018-1305: Medium severity Apache Tomcat vulnerability
Apache Tomcat versions 7.0.0 to 7.0.84, 8.0.0.RC1 to 8.0.49 and 8.5.0 to 8.5.27 only apply security constraints defined by Servlets once those Servlets are loaded. Depending on the order that Servlets load, some security constraints may not be applied leading to unintended resource exposure.
External References:
https://tomcat.apache.org/security-7.html#FixedinApacheTomcat7.0.85 https://tomcat.apache.org/security-8.html#FixedinApacheTomcat8.0.50 https://tomcat.apache.org/security-8.html#FixedinApacheTomcat8.5.28
Upstream Fixes:
Tomcat 7.0.x:
http://svn.apache.org/viewvc?view=rev&rev=1823322 http://svn.apache.org/viewvc?view=rev&rev=1824360
Tomcat 8.0.x:
http://svn.apache.org/viewvc?view=rev&rev=1823319 http://svn.apache.org/viewvc?view=rev&rev=1824359
Tomcat 8.5.x:
http://svn.apache.org/viewvc?view=rev&rev=1823314 http://svn.apache.org/viewvc?view=rev&rev=1824358
Other sources
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 0:7.0.76-9.el7 - Upgrade
Upgrade
redhat/tomcat7to a version that resolves this vulnerability.Fixed in 0:7.0.70-25.ep7.el6 - Upgrade
Upgrade
redhat/tomcat8to a version that resolves this vulnerability.Fixed in 0:8.0.36-29.ep7.el6 - Upgrade
Upgrade
redhat/tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.8-11.redhat_11.ep7.el6 - Upgrade
Upgrade
redhat/tomcat-vaultto a version that resolves this vulnerability.Fixed in 0:1.1.6-1.Final_redhat_1.1.ep7.el6 - Upgrade
Upgrade
redhat/tomcat7to a version that resolves this vulnerability.Fixed in 0:7.0.70-25.ep7.el7 - Upgrade
Upgrade
redhat/tomcat8to a version that resolves this vulnerability.Fixed in 0:8.0.36-29.ep7.el7 - Upgrade
Upgrade
redhat/tomcat-nativeto a version that resolves this vulnerability.Fixed in 0:1.2.8-11.redhat_11.ep7.el7 - Upgrade
Upgrade
redhat/tomcat-vaultto a version that resolves this vulnerability.Fixed in 0:1.1.6-1.Final_redhat_1.1.ep7.el7 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.5 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 7.0.85 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 8.5.28 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 7.0.85 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.0.50 - Upgrade
Upgrade
redhat/tomcatto a version that resolves this vulnerability.Fixed in 8.5.28 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.43-2~deb11u10Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcat 7to a version that resolves this vulnerability.Fixed in 7.0.85 - Upgrade
Upgrade
Apache Tomcat 8.0to a version that resolves this vulnerability.Fixed in 8.0.50 - Upgrade
Upgrade
Apache Tomcat 8.5to a version that resolves this vulnerability.Fixed in 8.5.28
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-1305?
CVE-2018-1305 is classified as a moderate severity vulnerability.
How do I fix CVE-2018-1305?
To fix CVE-2018-1305, upgrade Apache Tomcat to versions 7.0.85, 8.0.50, or 8.5.28 or later.
What versions of Apache Tomcat are affected by CVE-2018-1305?
CVE-2018-1305 affects Apache Tomcat versions 7.0.0 to 7.0.84, 8.0.0.RC1 to 8.0.49, and 8.5.0 to 8.5.27.
What type of vulnerability is CVE-2018-1305?
CVE-2018-1305 is a vulnerability that may lead to unintended resource exposure depending on the order in which Servlets are loaded.
Is there a workaround for CVE-2018-1305?
There are no recommended workarounds for CVE-2018-1305, the best course of action is to apply the necessary updates.