CVE Database
/

CVE-2017-7674

Back to search

CVE-2017-7674

Published: Aug 11, 2017

Modified: Sep 17, 2024

PUBLISHED

Description

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.0.M21
affected
8.5.0 to 8.5.15
affected
8.0.0.RC1 to 8.0.44
affected
7.0.41 to 7.0.78

References

RHSA-2017:1801
vendor-advisory
x_refsource_REDHAT
100280
vdb-entry
x_refsource_BID
DSA-3974
vendor-advisory
x_refsource_DEBIAN
RHSA-2017:1802
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3081
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now