cbcvebase.
CVE-2018-8014
published 2018-05-16

CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and…

PriorityP258critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
21.98%
97.4th percentile
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

Affected

19 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat
apachetomcat7.0.41 – 7.0.88
apachetomcat8.0.0 – 8.0.52
apachetomcat8.5.0 – 8.5.31
apachetomcat9.0.0 – 9.0.8
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
apache_software_foundationapache_tomcat
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiantomcat9
netapponcommand_unified_manager>= 7.3
netapponcommand_unified_manager>= 9.4

Detection & IOCsextracted from sources · hover to see the quote

  • Detect insecure CORS filter configuration where supportsCredentials is enabled for all origins (wildcard) in Apache Tomcat web.xml or context configuration
  • Flag Apache Tomcat deployments running versions 9.0.0.M1–9.0.8, 8.5.0–8.5.31, 8.0.0.RC1–8.0.52, or 7.0.41–7.0.88 that use the CORS filter without explicit configuration (i.e., relying on insecure defaults)
  • ·The vulnerability only affects deployments that use the CORS filter with default (unconfigured) settings; explicitly configured CORS filters are not impacted
  • ·The insecure default enables supportsCredentials for all origins; the dangerous combination to check for is cors.allowed.origins=* paired with cors.support.credentials=True

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_apache9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.