First published: Wed Oct 10 2018(Updated: )
It was discovered that Tomcat incorrectly handled returning redirects to a directory. A remote attacker could possibly use this issue with a specially crafted URL to redirect to arbitrary URIs.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libtomcat8-java | <8.0.32-1ubuntu1.8 | 8.0.32-1ubuntu1.8 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/tomcat8 | <8.0.32-1ubuntu1.8 | 8.0.32-1ubuntu1.8 |
Ubuntu | =16.04 | |
All of | ||
ubuntu/libtomcat7-java | <7.0.52-1ubuntu0.16 | 7.0.52-1ubuntu0.16 |
Ubuntu | =14.04 | |
All of | ||
ubuntu/tomcat7 | <7.0.52-1ubuntu0.16 | 7.0.52-1ubuntu0.16 |
Ubuntu | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Tomcat vulnerability is CVE-2018-11784.
The vulnerability allows a remote attacker to redirect users to arbitrary URIs.
This vulnerability affects Ubuntu 14.04 and Ubuntu 16.04.
To fix this vulnerability, update the libtomcat7-java, tomcat7, libtomcat8-java, or tomcat8 packages to version 7.0.52-1ubuntu0.16 or 8.0.32-1ubuntu1.8 depending on the version you have installed.
You can find more information about this vulnerability on the Ubuntu security advisory page at https://ubuntu.com/security/CVE-2018-11784.