CVE Database
/

CVE-2018-8014

Back to search

CVE-2018-8014

Published: May 16, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.8
affected
8.5.0 to 8.5.31
affected
8.0.0.RC1 to 8.0.52
affected
7.0.41 to 7.0.88

References

RHSA-2019:0451
vendor-advisory
x_refsource_REDHAT
RHSA-2018:2469
vendor-advisory
x_refsource_REDHAT
1041888
vdb-entry
x_refsource_SECTRACK
USN-3665-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2018:2470
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0450
vendor-advisory
x_refsource_REDHAT
104203
vdb-entry
x_refsource_BID
1040998
vdb-entry
x_refsource_SECTRACK
RHSA-2018:3768
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1529
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2205
vendor-advisory
x_refsource_REDHAT
DSA-4596
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now