CVE-2018-8014Initialization of a Resource with an Insecure Default in Apache Tomcat

Severity
9.8CRITICALNVD
EPSS
48.8%
top 2.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateOct 17

Description

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/tomcat7.0.417.0.88+5

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04

Patches

🔴Vulnerability Details

4
GHSA
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins2018-10-17
OSV
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins2018-10-17
CVEList
CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 92018-05-16
OSV
CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 92018-05-16

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2018-05-30
Red Hat
tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins2018-05-17
Debian
CVE-2018-8014: tomcat9 - The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to ...2018
Apache
Apache tomcat: CVE-2018-8014

💬Community

3
Bugzilla
CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins [epel-all]2018-05-18
Bugzilla
CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins2018-05-18
Bugzilla
CVE-2018-8014 tomcat: Insecure defaults in CORS filter enable 'supportsCredentials' for all origins [fedora-all]2018-05-18
CVE-2018-8014 — Apache Tomcat vulnerability | cvebase