CVE-2018-8034Improper Certificate Validation in Apache Tomcat

Severity
7.5HIGHNVD
EPSS
11.7%
top 6.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 1
Latest updateOct 17

Description

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/tomcat7.0.357.0.88+5
NVDoracle/retail_order_broker15.0, 5.1, 5.2+2

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04

Patches

🔴Vulnerability Details

5
GHSA
The host name verification missing in Apache Tomcat2018-10-17
OSV
The host name verification missing in Apache Tomcat2018-10-17
CVEList
CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing2018-08-01
OSV
tomcat7, tomcat8 vulnerabilities2018-07-25
OSV
CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing2018-07-24

📋Vendor Advisories

4
Ubuntu
Tomcat vulnerabilities2018-07-25
Red Hat
tomcat: Host name verification missing in WebSocket client2018-07-22
Debian
CVE-2018-8034: tomcat9 - The host name verification when using TLS with the WebSocket client was missing....2018
Apache
Apache tomcat: CVE-2018-8034

💬Community

3
Bugzilla
CVE-2018-8034 tomcat: host name verification missing in WebSocket client [fedora-all]2018-07-23
Bugzilla
CVE-2018-8034 tomcat: host name verification missing in WebSocket client [epel-all]2018-07-23
Bugzilla
CVE-2018-8034 tomcat: Host name verification missing in WebSocket client2018-07-23
CVE-2018-8034 — Improper Certificate Validation | cvebase