CVE Database
/

CVE-2018-8034

Back to search

CVE-2018-8034

Published: Aug 1, 2018

Modified: Oct 21, 2024

PUBLISHED

Description

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

VendorProductVersions

Apache Software Foundation

Apache Tomcat

affected
9.0.0.M1 to 9.0.9
affected
8.5.0 to 8.5.31
affected
8.0.0.RC1 to 8.0.52
affected
7.0.35 to 7.0.88

References

USN-3723-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:0451
vendor-advisory
x_refsource_REDHAT
DSA-4281
vendor-advisory
x_refsource_DEBIAN
1041374
vdb-entry
x_refsource_SECTRACK
RHSA-2019:0131
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0130
vendor-advisory
x_refsource_REDHAT
RHSA-2019:0450
vendor-advisory
x_refsource_REDHAT
104895
vdb-entry
x_refsource_BID
RHSA-2019:1160
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1162
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1159
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1161
vendor-advisory
x_refsource_REDHAT
RHSA-2019:1529
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2205
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3892
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now