CVE Database
/

CVE-2018-1305

Back to search

CVE-2018-1305

Published: Feb 23, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.84

References

103144
vdb-entry
x_refsource_BID
DSA-4281
vendor-advisory
x_refsource_DEBIAN
RHSA-2018:2939
vendor-advisory
x_refsource_REDHAT
RHSA-2018:0465
vendor-advisory
x_refsource_REDHAT
USN-3665-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:1320
vendor-advisory
x_refsource_REDHAT
RHSA-2018:0466
vendor-advisory
x_refsource_REDHAT
1040428
vdb-entry
x_refsource_SECTRACK
RHSA-2019:2205
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now