First published: Wed May 16 2018(Updated: )
Apache Tomcat through versions 7.0.88, 8.0.52, 8.5.31 and 9.0.8 have defaults settings for the CORS filter that are insecure and enable 'supportsCredentials' for all origins. Upstream announcement: <a href="https://lists.apache.org/thread.html/fbfb713e4f8a4c0f81089b89450828011343593800cae3fb629192b1@%3Cannounce.tomcat.apache.org%3E">https://lists.apache.org/thread.html/fbfb713e4f8a4c0f81089b89450828011343593800cae3fb629192b1@%3Cannounce.tomcat.apache.org%3E</a> Upstream bug: <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=62343">https://bz.apache.org/bugzilla/show_bug.cgi?id=62343</a> Upstream Patches: <a href="http://svn.apache.org/viewvc?view=rev&rev=1831726">http://svn.apache.org/viewvc?view=rev&rev=1831726</a> / trunk/9.0 <a href="http://svn.apache.org/viewvc?view=rev&rev=1831728">http://svn.apache.org/viewvc?view=rev&rev=1831728</a> / 8.5 <a href="http://svn.apache.org/viewvc?view=rev&rev=1831729">http://svn.apache.org/viewvc?view=rev&rev=1831729</a> / 8.0 <a href="http://svn.apache.org/viewvc?view=rev&rev=1831730">http://svn.apache.org/viewvc?view=rev&rev=1831730</a> / 7.0 External References: <a href="http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.9">http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.9</a> <a href="http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.32">http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.32</a> <a href="http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.53">http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.53</a> <a href="http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.89">http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.89</a>
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tomcat | <8.0.53 | 8.0.53 |
redhat/tomcat | <8.5.32 | 8.5.32 |
redhat/tomcat | <9.0.9 | 9.0.9 |
redhat/tomcat | <7.0.89 | 7.0.89 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.0.0RC1<8.0.53 | 8.0.53 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=9.0.0.M1<=9.0.8 | 9.0.9 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=7.0.41<7.0.88 | 7.0.88 |
maven/org.apache.tomcat.embed:tomcat-embed-core | >=8.5.0<8.5.32 | 8.5.32 |
Apache Tomcat | >=7.0.41<=7.0.88 | |
Apache Tomcat | >=8.0.0<=8.0.52 | |
Apache Tomcat | >=8.5.0<=8.5.31 | |
Apache Tomcat | >=9.0.0<=9.0.8 | |
Apache Tomcat | =8.0.0-rc1 | |
Apache Tomcat | =9.0.0-milestone1 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
Debian Debian Linux | =8.0 | |
NetApp OnCommand Insight | ||
Netapp Oncommand Unified Manager Vmware Vsphere | >=9.4 | |
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter Server | ||
Netapp Storage Automation Store | ||
All of | ||
Netapp Oncommand Unified Manager | >=7.3 | |
Microsoft Windows | ||
Apache Tomcat | =9.0.0-m1 | |
Netapp Oncommand Unified Manager | >=7.3 | |
Microsoft Windows | ||
debian/tomcat9 | 9.0.43-2~deb11u10 9.0.70-2 9.0.95-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8014 is a vulnerability that affects the default settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.41 to 7.0.88.
CVE-2018-8014 has a severity rating of 9.8 out of 10.
CVE-2018-8014 affects the CORS filter in Apache Tomcat and allows the 'supportsCredentials' option to be enabled for all origins, which can lead to insecure configurations.
To fix CVE-2018-8014, it is recommended to upgrade Apache Tomcat to version 9.0.9, 8.5.32, or 8.0.53, depending on your installed version.
You can find more information about CVE-2018-8014 in the references provided: [link1], [link2], [link3].