Severity
7.4HIGH
EPSS
1.5%
top 18.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 13

Description

Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

NVDapache/tomcat_native1.1.231.1.34+1
CVEListV5apache_software_foundation/apache_tomcat_native1.1.23 to 1.1.34, 1.2.0 to 1.2.16+1
Debiantomcat-native< 1.2.17-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-r94v-7v68-9rjq: Apache Tomcat Native 12022-05-13
OSV
CVE-2018-8020: Apache Tomcat Native 12018-07-31
CVEList
CVE-2018-8020: Apache Tomcat Native 12018-07-31

📋Vendor Advisories

2
Red Hat
tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates2018-07-21
Debian
CVE-2018-8020: tomcat-native - Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does n...2018

💬Community

3
Bugzilla
CVE-2018-8020 tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates [epel-all]2018-08-01
Bugzilla
CVE-2018-8020 tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates [fedora-all]2018-08-01
Bugzilla
CVE-2018-8020 tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates2018-05-23
CVE-2018-8020 (HIGH CVSS 7.4) | Apache Tomcat Native 1.2.0 to 1.2.1 | cvebase.io