| <!DOCTYPE html SYSTEM "about:legacy-compat"> |
| <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet" type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet" type="text/css"><title>Apache Tomcat® - Apache Tomcat 7 vulnerabilities</title><meta name="author" content="Apache Tomcat Project"><script src="https://www.apachecon.com/event-images/snippet.js"></script></head><body><div id="wrapper"><header id="header"><div class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img class="tomcat-logo pull-left noPrint" alt="Tomcat Home" src="res/images/tomcat.png"></a><h1 class="pull-left">Apache Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a href="https://www.apache.org/foundation/contributing.html" target="_blank" class="pull-left"><img src="https://www.apache.org/images/SupportApache-small.png" class="support-asf" alt="Support Apache"></a><a href="http://www.apache.org/" target="_blank" class="pull-left"><img src="res/images/asf_logo_wide.svg" class="asf-logo" alt="The Apache Software Foundation"></a></div></div></header><main id="middle"><div><div id="mainLeft"><div id="nav-wrapper"><form action="https://www.google.com/search" method="get"><div class="searchbox"><input value="tomcat.apache.org" name="sitesearch" type="hidden"><input aria-label="Search text" placeholder="Search…" required="required" name="q" id="query" type="search"><button>GO</button></div></form><div class="asfevents"><a class="acevent" data-format="square" data-width="150"></a></div><nav><div><h2>Apache Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a href="./whichversion.html">Which version?</a></li><li><a href="https://tomcat.apache.org/download-11.cgi">Tomcat 11</a></li><li><a href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool for Jakarta EE</a></li><li><a href="https://tomcat.apache.org/download-connectors.cgi">Tomcat Connectors</a></li><li><a href="https://tomcat.apache.org/download-native.cgi">Tomcat Native</a></li><li><a href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a href="./tomcat-11.0-doc/index.html">Tomcat 11.0</a></li><li><a href="./tomcat-10.1-doc/index.html">Tomcat 10.1</a></li><li><a href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a href="./upgrading.html">Upgrading</a></li><li><a href="./connectors-doc/index.html">Tomcat Connectors</a></li><li><a href="./native-doc/index.html">Tomcat Native 2</a></li><li><a href="./native-1.3-doc/index.html">Tomcat Native 1.3</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a href="./migration.html">Migration Guide</a></li><li><a href="./presentations.html">Presentations</a></li><li><a href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a href="./security.html">Security Reports</a></li><li><a href="./findhelp.html">Find help</a></li><li><a href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug Database</a></li></ul></div><div><h2>Get Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a href="./source.html">Source code</a></li><li><a href="./ci.html">Buildbot</a></li><li><a href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li></ul></div><div><h2>Misc</h2><ul><li><a href="./whoweare.html">Who We Are</a></li><li><a href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a href="./heritage.html">Heritage</a></li><li><a href="http://www.apache.org">Apache Home</a></li><li><a href="./resources.html">Resources</a></li><li><a href="./contact.html">Contact</a></li><li><a href="./legal.html">Legal</a></li><li><a href="https://privacy.apache.org/policies/privacy-policy-public.html">Privacy</a></li><li><a href="https://www.apache.org/foundation/contributing.html">Support Apache</a></li><li><a href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3 id="Apache_Tomcat_7.x_vulnerabilities">Apache Tomcat 7.x vulnerabilities</h3><div class="text"> |
| <p>This page lists all security vulnerabilities fixed in released versions |
| of Apache Tomcat<sup>®</sup> 7.x. Each vulnerability is given a |
| <a href="security-impact.html">security impact rating</a> by the Apache |
| Tomcat security team — please note that this rating may vary from |
| platform to platform. We also list the versions of Apache Tomcat the flaw |
| is known to affect, and where a flaw has not been verified list the |
| version with a question mark.</p> |
| |
| <p><strong>Note:</strong> Vulnerabilities that are not Tomcat vulnerabilities |
| but have either been incorrectly reported against Tomcat or where Tomcat |
| provides a workaround are listed at the end of this page.</p> |
| |
| <p><strong>Please note that Tomcat 7.0.x has reached |
| <a href="tomcat-70-eol.html">end of life</a> and is no longer supported. |
| Further vulnerabilities in the 7.0.x branch will not be fixed. Users |
| should upgrade to 9.0.x or later to obtain security fixes.</strong></p> |
| |
| <p>The published CVE records for vulnerabilities reported from 2023 onwards |
| include affected version information for EOL versions. By default, the |
| status for EOL versions is reported as unknown. <strong>Where additional |
| information is available, the published CVE record may be updated to |
| indicate whether an EOL version is affected / not-affected. Only the |
| published CVE record will be updated. This page will NOT be updated if |
| the status of an EOL version is updated. No email announcement will be |
| made if if the status of an EOL version is updated.</strong></p> |
| |
| <p>Please note that binary patches are never provided. If you need to |
| apply a source code patch, use the building instructions for the |
| Apache Tomcat version that you are using. For Tomcat 7.0 those are |
| <a href="/tomcat-7.0-doc/building.html"><code>building.html</code></a> and |
| <a href="/tomcat-7.0-doc/BUILDING.txt"><code>BUILDING.txt</code></a>. |
| Both files can be found in the <code>webapps/docs</code> subdirectory |
| of a binary distributive. You may also want to review the |
| <a href="/tomcat-7.0-doc/security-howto.html">Security Considerations</a> |
| page in the documentation.</p> |
| |
| <p>If you need help on building or configuring Tomcat or other help on |
| following the instructions to mitigate the known vulnerabilities listed |
| here, please send your questions to the public |
| <a href="lists.html">Tomcat Users mailing list</a> |
| </p> |
| |
| <p>If you have encountered an unlisted security vulnerability or other |
| unexpected behaviour that has <a href="security-impact.html">security |
| impact</a>, or if the descriptions here are incomplete, |
| please report them privately to the |
| <a href="security.html">Tomcat Security Team</a>. Thank you. |
| </p> |
| |
| </div><h3 id="Table_of_Contents">Table of Contents</h3><div class="text"> |
| <ul><li><a href="#Fixed_in_Apache_Tomcat_7.0.109">Fixed in Apache Tomcat 7.0.109</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.108">Fixed in Apache Tomcat 7.0.108</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.107">Fixed in Apache Tomcat 7.0.107</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.105">Fixed in Apache Tomcat 7.0.105</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.104">Fixed in Apache Tomcat 7.0.104</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.100">Fixed in Apache Tomcat 7.0.100</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.99">Fixed in Apache Tomcat 7.0.99</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.94">Fixed in Apache Tomcat 7.0.94</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.91">Fixed in Apache Tomcat 7.0.91</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.90">Fixed in Apache Tomcat 7.0.90</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.89">Fixed in Apache Tomcat 7.0.89</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.88">Fixed in Apache Tomcat 7.0.88</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.85">Fixed in Apache Tomcat 7.0.85</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.84">Fixed in Apache Tomcat 7.0.84</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.82">Fixed in Apache Tomcat 7.0.82</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.81">Fixed in Apache Tomcat 7.0.81</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.79">Fixed in Apache Tomcat 7.0.79</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.78">Fixed in Apache Tomcat 7.0.78</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.77">Fixed in Apache Tomcat 7.0.77</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.76">Fixed in Apache Tomcat 7.0.76</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.75">Fixed in Apache Tomcat 7.0.75</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.73">Fixed in Apache Tomcat 7.0.73</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.72">Fixed in Apache Tomcat 7.0.72</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.70">Fixed in Apache Tomcat 7.0.70</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.68">Fixed in Apache Tomcat 7.0.68</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.67">Fixed in Apache Tomcat 7.0.67</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.65">Fixed in Apache Tomcat 7.0.65</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.59">Fixed in Apache Tomcat 7.0.59</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.55">Fixed in Apache Tomcat 7.0.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.54">Fixed in Apache Tomcat 7.0.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.53">Fixed in Apache Tomcat 7.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.52">Fixed in Apache Tomcat 7.0.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.50">Fixed in Apache Tomcat 7.0.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.47">Fixed in Apache Tomcat 7.0.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.40">Fixed in Apache Tomcat 7.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.33">Fixed in Apache Tomcat 7.0.33</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.32">Fixed in Apache Tomcat 7.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.30">Fixed in Apache Tomcat 7.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.28">Fixed in Apache Tomcat 7.0.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.23">Fixed in Apache Tomcat 7.0.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.22">Fixed in Apache Tomcat 7.0.22</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.21">Fixed in Apache Tomcat 7.0.21</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.20">Fixed in Apache Tomcat 7.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.19">Fixed in Apache Tomcat 7.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.14">Fixed in Apache Tomcat 7.0.14</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.12">Fixed in Apache Tomcat 7.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.11">Fixed in Apache Tomcat 7.0.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.8">Fixed in Apache Tomcat 7.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.6">Fixed in Apache Tomcat 7.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.5">Fixed in Apache Tomcat 7.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.4">Fixed in Apache Tomcat 7.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_7.0.2">Fixed in Apache Tomcat 7.0.2</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</a></li></ul> |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.109"><span class="pull-right">26 April 2021</span> Fixed in Apache Tomcat 7.0.109</h3><div class="text"> |
| |
| <p><strong>Low: Authentication weakness</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30640" rel="nofollow">CVE-2021-30640</a></p> |
| |
| <p>Queries made by the JNDI Realm did not always correctly escape |
| parameters. Parameter values could be sourced from user provided data (eg |
| user names) as well as configuration data provided by an administrator. |
| In limited circumstances it was possible for users to authenticate using |
| variations of their user name and/or to bypass some of the protection |
| provided by the LockOut Realm.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/e21eb4764ccda55e5a35a5a7c19a6fd2b0757fe9">e21eb476</a>.</p> |
| |
| <p>This issue was reported publicly as <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=65224">65224</a>.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.108</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.108"><span class="pull-right">5 February 2021</span> Fixed in Apache Tomcat 7.0.108</h3><div class="text"> |
| |
| <p><strong>Low: Fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> was incomplete</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25329" rel="nofollow">CVE-2021-25329</a></p> |
| |
| <p>The fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> was incomplete. When using a |
| highly unlikely configuration edge case, the Tomcat instance was still |
| vulnerable to <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a>. Note that both the previously |
| published prerequisites for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> and the previously |
| published non-upgrade mitigations for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a> also apply to |
| this issue.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/74b105657ffbd1d1de80455f03446c3bbf30d1f5">74b10565</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security team by Trung Pham |
| of Viettel Cyber Security on 12 January 2021. The issue was made public |
| on 1 March 2021.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.107</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.107"><span class="pull-right">11 November 2020</span> Fixed in Apache Tomcat 7.0.107</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-24122" rel="nofollow">CVE-2021-24122</a></p> |
| |
| <p>When serving resources from a network location using the NTFS file system |
| it was possible to bypass security constraints and/or view the source |
| code for JSPs in some configurations. The root cause was the unexpected |
| behaviour of the JRE API <code>File.getCanonicalPath()</code> which in |
| turn was caused by the inconsistent behaviour of the Windows API |
| (<code>FindFirstFileW</code>) in some circumstances. |
| </p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/800b03140e640f8892f27021e681645e8e320177">800b0314</a>.</p> |
| |
| <p>This issue was reported the Apache Tomcat Security team by Ilja Brander |
| on 26 October 2020. The issue was made public on 14 January 2021.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.106</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.105"><span class="pull-right">7 July 2020</span> Fixed in Apache Tomcat 7.0.105</h3><div class="text"> |
| |
| <p><strong>Important: WebSocket DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13935" rel="nofollow">CVE-2020-13935</a></p> |
| |
| <p>The payload length in a WebSocket frame was not correctly validated. |
| Invalid payload lengths could trigger an infinite loop. Multiple requests |
| with invalid payload lengths could lead to a denial of service.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/f9f75c14678b68633f79030ddf4ff827f014cc84">f9f75c14</a> and |
| <a href="https://github.com/apache/tomcat/commit/4c04982870d6e730c38e21e58fb653b7cf723784">4c049828</a>.</p> |
| |
| <p>This issue was reported publicly via the Apache Bugzilla instance on 28 |
| June 2020 and included references to high CPU but no specific reference |
| to denial of service. The associated DoS risks were identified by the |
| Apache Tomcat Security Team the same day. The issue was made public on 14 |
| July 2020.</p> |
| |
| <p>Affects: 7.0.27 to 7.0.104</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.104"><span class="pull-right">16 May 2020</span> Fixed in Apache Tomcat 7.0.104</h3><div class="text"> |
| |
| <p><strong>High: Remote Code Execution via session persistence</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484" rel="nofollow">CVE-2020-9484</a></p> |
| |
| <p>If:</p> |
| <ul> |
| <li>an attacker is able to control the contents and name of a file on the |
| server; and</li> |
| <li>the server is configured to use the <code>PersistenceManager</code> |
| with a <code>FileStore</code>; and</li> |
| <li>the <code>PersistenceManager</code> is configured with |
| <code>sessionAttributeValueClassNameFilter="null"</code> (the default |
| unless a <code>SecurityManager</code> is used) or a sufficiently lax |
| filter to allow the attacker provided object to be deserialized; |
| and</li> |
| <li>the attacker knows the relative file path from the storage location |
| used by <code>FileStore</code> to the file the attacker has control |
| over;</li> |
| </ul> |
| <p>then, using a specifically crafted request, the attacker will be able to |
| trigger remote code execution via deserialization of the file under their |
| control.</p> |
| |
| <p><strong>Note:</strong> All of conditions above must be true for the |
| attack to succeed.</p> |
| |
| <p>As an alternative to upgrading to 7.0.104 or later, users may configure |
| the <code>PersistenceManager</code> with an appropriate value for |
| <code>sessionAttributeValueClassNameFilter</code> to ensure that only |
| application provided attributes are serialized and deserialized.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/53e30390943c18fca0c9e57dbcc14f1c623cfd06">53e30390</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by by jarvis |
| threedr3am of pdd security research on 12 April 2020. The issue was made |
| public on 20 May 2020.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.103</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.100"><span class="pull-right">14 February 2020</span> Fixed in Apache Tomcat 7.0.100</h3><div class="text"> |
| |
| <p><strong>High: AJP Request Injection and potential Remote Code Execution</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1938" rel="nofollow">CVE-2020-1938</a></p> |
| |
| <p>When using the Apache JServ Protocol (AJP), care must be taken when |
| trusting incoming connections to Apache Tomcat. Tomcat treats AJP |
| connections as having higher trust than, for example, a similar HTTP |
| connection. If such connections are available to an attacker, they can be |
| exploited in ways that may be surprising. Prior to Tomcat 7.0.100, Tomcat |
| shipped with an AJP Connector enabled by default that listened on all |
| configured IP addresses. It was expected (and recommended in the security |
| guide) that this Connector would be disabled if not required.</p> |
| <p>Prior to this vulnerability report, the known risks of an attacker being |
| able to access the AJP port directly were:</p> |
| <ul> |
| <li>bypassing security checks based on client IP address</li> |
| <li>bypassing user authentication if Tomcat was configured to trust |
| authentication data provided by the reverse proxy</li> |
| </ul> |
| <p>This vulnerability report identified a mechanism that allowed the |
| following:</p> |
| <ul> |
| <li>returning arbitrary files from anywhere in the web application |
| including under the WEB-INF and META-INF directories or any other |
| location reachable via ServletContext.getResourceAsStream()</li> |
| <li>processing any file in the web application as a JSP</li> |
| </ul> |
| <p>Further, if the web application allowed file upload and stored those |
| files within the web application (or the attacker was able to control |
| the content of the web application by some other means) then this, along |
| with the ability to process a file as a JSP, made remote code execution |
| possible.</p> |
| <p>It is important to note that mitigation is only required if an AJP port |
| is accessible to untrusted users. Users wishing to take a |
| defence-in-depth approach and block the vector that permits returning |
| arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31 |
| or later. Users should note that a number of changes were made to the |
| default AJP Connector configuration in 7.0.100 to harden the default |
| configuration. It is likely that users upgrading to 7.0.100 or later |
| will need to make small changes to their configurations as a result.</p> |
| |
| <p>This was fixed with commits |
| <a href="https://github.com/apache/tomcat/commit/0d633e72ebc7b3c242d0081c23bba5e4dacd9b72">0d633e72</a>, |
| <a href="https://github.com/apache/tomcat/commit/40d5d93bd284033cf4a1f77f5492444f83d803e2">40d5d93b</a>, |
| <a href="https://github.com/apache/tomcat/commit/b99fba5bd796d876ea536e83299603443842feba">b99fba5b</a> and |
| <a href="https://github.com/apache/tomcat/commit/f7180bafc74cb1250c9e9287b68a230f0e1f4645">f7180baf</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team on 3 January |
| 2020. The issue was made public on 24 February 2020.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.99</p> |
| |
| <p><strong>Low: HTTP Request Smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1935" rel="nofollow">CVE-2020-1935</a></p> |
| |
| <p>The HTTP header parsing code used an approach to end-of-line (EOL) |
| parsing that allowed some invalid HTTP headers to be parsed as valid. This |
| led to a possibility of HTTP Request Smuggling if Tomcat was |
| located behind a reverse proxy that incorrectly handled the invalid |
| Transfer-Encoding header in a particular manner. Such a reverse proxy is |
| considered unlikely.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/702bf15bea292915684d931526d95d4990b2e73d">702bf15b</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by @ZeddYu |
| on 25 December 2019. The issue was made public on 24 |
| February 2020.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.99</p> |
| |
| <p><strong>Low: HTTP Request Smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17569" rel="nofollow">CVE-2019-17569</a></p> |
| |
| <p>The refactoring in 7.0.98 introduced a regression. The result of the |
| regression was that invalid Transfer-Encoding headers were incorrectly |
| processed leading to a possibility of HTTP Request Smuggling if Tomcat was |
| located behind a reverse proxy that incorrectly handled the invalid |
| Transfer-Encoding header in a particular manner. Such a reverse proxy is |
| considered unlikely.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/b191a0d9cf06f4e04257c221bfe41d2b108a9cc8">b191a0d9</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by @ZeddYu |
| on 12 December 2019. The issue was made public on 24 |
| February 2020.</p> |
| |
| <p>Affects: 7.0.98 to 7.0.99</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.99"><span class="pull-right">17 December 2019</span> Fixed in Apache Tomcat 7.0.99</h3><div class="text"> |
| |
| <p><strong>Low: Session fixation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17563" rel="nofollow">CVE-2019-17563</a></p> |
| |
| <p>When using FORM authentication there was a narrow window where an |
| attacker could perform a session fixation attack. The window was |
| considered too narrow for an exploit to be practical but, erring on the |
| side of caution, this issue has been treated as a security |
| vulnerability.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/ab72a106fe5d992abddda954e30849d7cf8cc583">ab72a106</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by William |
| Marlow (IBM) on 19 November 2019. The issue was made public on 18 |
| December 2019.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.98</p> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.98 but the |
| release vote for the 7.0.98 release candidate did not pass. Therefore, |
| although users must download 7.0.99 to obtain a version that includes |
| the fix for this issue, version78.0.98 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Moderate: Local Privilege Escalation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12418" rel="nofollow">CVE-2019-12418</a></p> |
| |
| <p>When Tomcat is configured with the JMX Remote Lifecycle Listener, a local |
| attacker without access to the Tomcat process or configuration files is |
| able to manipulate the RMI registry to perform a man-in-the-middle attack |
| to capture user names and passwords used to access the JMX interface. The |
| attacker can then use these credentials to access the JMX interface and |
| gain complete control over the Tomcat instance.</p> |
| <p>The JMX Remote Lifecycle Listener will be deprecated in future Tomcat |
| releases, will be removed for Tomcat 10 and may be removed from all |
| Tomcat releases some time after 31 December 2020.</p> |
| <p>Users should also be aware of <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2684" rel="nofollow">CVE-2019-2684</a>, a JRE |
| vulnerability that enables this issue to be exploited remotely.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/bef3f40400243348d12f4abfe9b413f43897c02b">bef3f404</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by An Trinh of |
| Viettel Cyber Security on 10 October 2019. The issue was made public on 18 |
| December 2019.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.97</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.94"><span class="pull-right">12 April 2019</span> Fixed in Apache Tomcat 7.0.94</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution on Windows</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0232" rel="nofollow">CVE-2019-0232</a></p> |
| |
| <p>When running on Windows with enableCmdLineArguments enabled, the CGI |
| Servlet is vulnerable to Remote Code Execution due to a bug in the way |
| the JRE passes command line arguments to Windows. The CGI Servlet is |
| disabled by default. For a detailed explanation of the JRE behaviour, see |
| <a href="https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html">Markus |
| Wulftange's blog</a> and this archived |
| <a href="https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/">MSDN |
| blog</a>.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/7f0221b904956359f2d739aa3a2b53f8c12ed8c7">7f0221b9</a>.</p> |
| |
| <p>This issue was identified by Nightwatch Cybersecurity Research and |
| reported to the Apache Tomcat security team via the bug bounty program |
| sponsored by the EU FOSSA-2 project on 3rd March 2019. The issue was made |
| public on 10 April 2019.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.93</p> |
| |
| <p><strong>Low: XSS in SSI printenv</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-0221" rel="nofollow">CVE-2019-0221</a></p> |
| |
| <p>The SSI printenv command echoes user provided data without escaping and |
| is, therefore, vulnerable to XSS. SSI is disabled by default. The |
| printenv command is intended for debugging and is unlikely to be present |
| in a production website.</p> |
| |
| <p>This was fixed with commit |
| <a href="https://github.com/apache/tomcat/commit/44ec74c44dcd05cd7e90967c04d40b51440ecd7e">44ec74c4</a>.</p> |
| |
| <p>This issue was identified by Nightwatch Cybersecurity Research and |
| reported to the Apache Tomcat security team via the bug bounty program |
| sponsored by the EU FOSSA-2 project on 7th March 2019. The issue was made |
| public on 17 May 2019.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.93</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.91"><span class="pull-right">19 September 2018</span> Fixed in Apache Tomcat 7.0.91</h3><div class="text"> |
| |
| <p><strong>Moderate: Open Redirect</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11784" rel="nofollow">CVE-2018-11784</a></p> |
| |
| <p>When the default servlet returned a redirect to a directory (e.g. |
| redirecting to <code>/foo/</code> when the user requested |
| <code>/foo</code>) a specially crafted URL could be used to cause the |
| redirect to be generated to any URI of the attackers choice.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1840057">1840057</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by Sergey |
| Bobrov on 28 August 2018 and made public on 3 October 2018.</p> |
| |
| <p>Affects: 7.0.23 to 7.0.90</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.90"><span class="pull-right">7 July 2018</span> Fixed in Apache Tomcat 7.0.90</h3><div class="text"> |
| |
| <p><strong>Low: host name verification missing in WebSocket client</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8034" rel="nofollow">CVE-2018-8034</a></p> |
| |
| <p>The host name verification when using TLS with the WebSocket client was |
| missing. It is now enabled by default.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1833760">1833760</a>.</p> |
| |
| <p>This issue was reported publicly on 11 June 2018 and formally announced as |
| a vulnerability on 22 July 2018.</p> |
| |
| <p>Affects: 7.0.25 to 7.0.88</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.89"><span class="pull-right">not released</span> Fixed in Apache Tomcat 7.0.89</h3><div class="text"> |
| |
| <p><strong>Low: CORS filter has insecure defaults</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8014" rel="nofollow">CVE-2018-8014</a></p> |
| |
| <p>The defaults settings for the CORS filter are insecure and enable |
| <code>supportsCredentials</code> for all origins. It is expected that |
| users of the CORS filter will have configured it appropriately for their |
| environment rather than using it in the default configuration. Therefore, |
| it is expected that most users will not be impacted by this issue.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1831730">1831730</a>.</p> |
| |
| <p>This issue was reported publicly on 1 May 2018 and formally announced as |
| a vulnerability on 16 May 2018.</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.88"><span class="pull-right">16 May 2018</span> Fixed in Apache Tomcat 7.0.88</h3><div class="text"> |
| |
| <p><strong>Important: A bug in the UTF-8 decoder can lead to DoS</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1336" rel="nofollow">CVE-2018-1336</a></p> |
| |
| <p>An improper handing of overflow in the UTF-8 decoder with |
| supplementary characters can lead to an infinite loop in the |
| decoder causing a Denial of Service.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1830376">1830376</a>.</p> |
| |
| <p>This issue was reported publicly on 6 April 2018 and formally announced as |
| a vulnerability on 22 July 2018.</p> |
| |
| <p>Affects: 7.0.28 to 7.0.88</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.85"><span class="pull-right">13 February 2018</span> Fixed in Apache Tomcat 7.0.85</h3><div class="text"> |
| |
| <p><strong>Important: Security constraint annotations applied too |
| late</strong> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1305" rel="nofollow">CVE-2018-1305</a></p> |
| |
| <p>Security constraints defined by annotations of Servlets were only applied |
| once a Servlet had been loaded. Because security constraints defined in |
| this way apply to the URL pattern and any URLs below that point, it was |
| possible - depending on the order Servlets were loaded - for some |
| security constraints not to be applied. This could have exposed resources |
| to users who were not authorised to access them.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1823322">1823322</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1824360">1824360</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security on 1 February |
| 2018 and made public on 23 February 2018.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.84</p> |
| |
| <p><strong>Important: Security constraints mapped to context root are |
| ignored</strong> <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1304" rel="nofollow">CVE-2018-1304</a></p> |
| |
| <p>The URL pattern of "" (the empty string) which exactly maps to the |
| context root was not correctly handled when used as part of a security |
| constraint definition. This caused the constraint to be ignored. It was, |
| therefore, possible for unauthorised users to gain access to web |
| application resources that should have been protected. Only security |
| constraints with a URL pattern of the empty string were affected.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1823309">1823309</a>.</p> |
| |
| <p>This issue was reported publicly as <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=62067">62067</a> on 31 January 2018 |
| and the security implications identified by the Apache Tomcat Security |
| Team the same day. It was made public on 23 February 2018.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.84</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.84"><span class="pull-right">24 January 2018</span> Fixed in Apache Tomcat 7.0.84</h3><div class="text"> |
| |
| <p><strong>Low: Incorrectly documented CGI search algorithm</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-15706" rel="nofollow">CVE-2017-15706</a></p> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.83 but the |
| release vote for the 7.0.83 release candidate did not pass. Therefore, |
| although users must download 7.0.84 to obtain a version that includes |
| the fix for this issue, version 7.0.83 is not included in the list of |
| affected versions.</i></p> |
| |
| <p>As part of the fix for bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=61201">61201</a>, the description of the |
| search algorithm used by the CGI Servlet to identify which script to |
| execute was updated. The update was not correct. As a result, some |
| scripts may have failed to execute as expected and other scripts may have |
| been executed unexpectedly. Note that the behaviour of the CGI servlet |
| has remained unchanged in this regard. It is only the documentation of |
| the behaviour that was wrong and has been corrected.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1814828">1814828</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team by Jan Michael |
| Greiner on 17 September 2017 and made public on 31 January 2018.</p> |
| |
| <p>Affects: 7.0.79 to 7.0.82</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.82"><span class="pull-right">4 October 2017</span> Fixed in Apache Tomcat 7.0.82</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12617" rel="nofollow">CVE-2017-12617</a></p> |
| |
| <p>When running with HTTP PUTs enabled (e.g. via setting the |
| <code>readonly</code> initialisation parameter of the Default servlet to |
| false) it was possible to upload a JSP file to the server via a specially |
| crafted request. This JSP could then be requested and any code it |
| contained would be executed by the server.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1809978">1809978</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1809992">1809992</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1810014">1810014</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1810026">1810026</a>.</p> |
| |
| <p>This issue was first reported publicly followed by multiple reports to |
| the Apache Tomcat Security Team on 20 September 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.81</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.81"><span class="pull-right">16 August 2017</span> Fixed in Apache Tomcat 7.0.81</h3><div class="text"> |
| |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12616" rel="nofollow">CVE-2017-12616</a></p> |
| |
| <p>When using a VirtualDirContext it was possible to bypass security |
| constraints and/or view the source code of JSPs for resources served by |
| the VirtualDirContext using a specially crafted request.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1804729">1804729</a>.</p> |
| |
| <p>This issue was identified by the Tomcat Security Team on 10 August 2017 |
| and made public on 19 September 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.80</p> |
| |
| <p><strong>Important: Remote Code Execution</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12615" rel="nofollow">CVE-2017-12615</a></p> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.80 but the |
| release vote for the 7.0.81 release candidate did not pass. Therefore, |
| although users must download 7.0.81 to obtain a version that includes |
| the fix for this issue, version 7.0.80 is not included in the list of |
| affected versions.</i></p> |
| |
| <p>When running on Windows with HTTP PUTs enabled (e.g. via setting the |
| <code>readonly</code> initialisation parameter of the Default to false) |
| it was possible to upload a JSP file to the server via a specially |
| crafted request. This JSP could then be requested and any code it |
| contained would be executed by the server.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1804604">1804604</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1804729">1804729</a>.</p> |
| |
| <p>This issue was reported responsibly to the Apache Tomcat Security Team by |
| iswin from 360-sg-lab (360观星实验室) on 26 July 2017 and made public on 19 |
| September 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.79</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.79"><span class="pull-right">1 July 2017</span> Fixed in Apache Tomcat 7.0.79</h3><div class="text"> |
| |
| <p><strong>Moderate: Cache Poisoning</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7674" rel="nofollow">CVE-2017-7674</a></p> |
| |
| <p>The CORS Filter did not add an HTTP Vary header indicating that the |
| response varies depending on Origin. This permitted client and server |
| side cache poisoning in some circumstances.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1795816">1795816</a>.</p> |
| |
| <p>The issue was reported as bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=61101">61101</a> on 16 May 2017. The full |
| implications of this issue were identified by the Tomcat Security Team |
| the same day. This issue was made public on 10 August 2017.</p> |
| |
| <p>Affects: 7.0.41 to 7.0.78</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.78"><span class="pull-right">16 May 2017</span> Fixed in Apache Tomcat 7.0.78</h3><div class="text"> |
| |
| <p><strong>Important: Security Constraint Bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5664" rel="nofollow">CVE-2017-5664</a></p> |
| |
| <p>The error page mechanism of the Java Servlet Specification requires that, |
| when an error occurs and an error page is configured for the error that |
| occurred, the original request and response are forwarded to the error |
| page. This means that the request is presented to the error page with the |
| original HTTP method.</p> |
| |
| <p>If the error page is a static file, expected behaviour is to serve content |
| of the file as if processing a GET request, regardless of the actual HTTP |
| method. Tomcat's Default Servlet did not do this. Depending on the |
| original request this could lead to unexpected and undesirable results for |
| static error pages including, if the DefaultServlet is configured to |
| permit writes, the replacement or removal of the custom error page.</p> |
| |
| <p>Notes for other user provided error pages:</p> |
| <ul> |
| <li>Unless explicitly coded otherwise, JSPs ignore the HTTP method. |
| JSPs used as error pages must ensure that they handle any error |
| dispatch as a GET request, regardless of the actual method.</li> |
| <li>By default, the response generated by a Servlet does depend on the |
| HTTP method. Custom Servlets used as error pages must ensure that |
| they handle any error dispatch as a GET request, regardless of the |
| actual method.</li> |
| </ul> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1793471">1793471</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1793491">1793491</a>.</p> |
| |
| <p>This issue was reported responsibly to the Apache Tomcat Security Team by |
| Aniket Nandkishor Kulkarni from Tata Consultancy Services Ltd, Mumbai, |
| India as a vulnerability that allowed the restrictions on OPTIONS and |
| TRACE requests to be bypassed on 21 April 2017. The full implications of |
| this issue were identified by the Tomcat Security Team on 24 April 2017. |
| This issue was made public on 6 June 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.77</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.77"><span class="pull-right">2 April 2017</span> Fixed in Apache Tomcat 7.0.77</h3><div class="text"> |
| |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5647" rel="nofollow">CVE-2017-5647</a></p> |
| |
| <p>A bug in the handling of the pipelined requests when send file was used |
| resulted in the pipelined request being lost when send file processing of |
| the previous request completed. This could result in responses appearing |
| to be sent for the wrong request. For example, a user agent that sent |
| requests A, B and C could see the correct response for request A, the |
| response for request C for request B and no response for request C.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1789008">1789008</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 20 |
| March 2017 and made public on 10 April 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.76</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.76"><span class="pull-right">16 March 2017</span> Fixed in Apache Tomcat 7.0.76</h3><div class="text"> |
| |
| <p><strong>Low: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5648" rel="nofollow">CVE-2017-5648</a></p> |
| |
| <p>While investigating bug 60718, it was noticed that some calls to |
| application listeners did not use the appropriate facade object. When |
| running an untrusted application under a SecurityManager, it was |
| therefore possible for that untrusted application to retain a reference |
| to the request or response object and thereby access and/or modify |
| information associated with another web application.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1785777">1785777</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 20 |
| March 2017 and made public on 10 April 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.75</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.75"><span class="pull-right">24 January 2017</span> Fixed in Apache Tomcat 7.0.75</h3><div class="text"> |
| |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8745" rel="nofollow">CVE-2016-8745</a></p> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.74 but the |
| release vote for the 7.0.74 release candidate did not pass. Therefore, |
| although users must download 7.0.75 to obtain a version that includes |
| the fix for this issue, version 7.0.74 is not included in the list of |
| affected versions.</i></p> |
| |
| <p>A bug in the error handling of the send file code for the NIO HTTP |
| connector resulted in the current Processor object being added to the |
| Processor cache multiple times. This in turn meant that the same |
| Processor could be used for concurrent requests. Sharing a Processor can |
| result in information leakage between requests including, but not limited |
| to, session ID and the response body.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1777471">1777471</a>.</p> |
| |
| <p>This issue was identified as affecting 7.0.x by the Apache Tomcat Security |
| Team on 3 January 2016 and made public on 5 January 2017.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.73</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.73"><span class="pull-right">14 November 2016</span> Fixed in Apache Tomcat 7.0.73</h3><div class="text"> |
| |
| <p><strong>Important: Remote Code Execution</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8735" rel="nofollow">CVE-2016-8735</a></p> |
| |
| <p>The <code>JmxRemoteLifecycleListener</code> was not updated to take |
| account of Oracle's fix for <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3427" rel="nofollow">CVE-2016-3427</a>. Therefore, Tomcat |
| installations using this listener remained vulnerable to a similar remote |
| code execution vulnerability. This issue has been rated as important |
| rather than critical due to the small number of installations using this |
| listener and that it would be highly unusual for the JMX ports to be |
| accessible to an attacker even when the listener is used.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1767676">1767676</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team on 19 October |
| 2016 and made public on 22 November 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.72</p> |
| |
| <p><strong>Important: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816" rel="nofollow">CVE-2016-6816</a></p> |
| |
| <p>The code that parsed the HTTP request line permitted invalid characters. |
| This could be exploited, in conjunction with a proxy that also permitted |
| the invalid characters but with a different interpretation, to inject |
| data into the HTTP response. By manipulating the HTTP response the |
| attacker could poison a web-cache, perform an XSS attack and/or obtain |
| sensitive information from requests other then their own.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1767675">1767675</a>.</p> |
| |
| <p>This issue was reported to the Apache Tomcat Security Team on 11 |
| October 2016 and made public on 22 November 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.72</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.72"><span class="pull-right">19 September 2016</span> Fixed in Apache Tomcat 7.0.72</h3><div class="text"> |
| |
| <p><i>Note: The issues below were fixed in Apache Tomcat 7.0.71 but the |
| release vote for the 7.0.71 release candidate did not pass. Therefore, |
| although users must download 7.0.72 to obtain a version that includes |
| fixes for these issues, version 7.0.71 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Unrestricted Access to Global Resources</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6797" rel="nofollow">CVE-2016-6797</a></p> |
| |
| <p>The ResourceLinkFactory did not limit web application access to global |
| JNDI resources to those resources explicitly linked to the web |
| application. Therefore, it was possible for a web application to access |
| any global JNDI resource whether an explicit ResourceLink had been |
| configured or not.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1757275">1757275</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 18 |
| January 2016 and made public on 27 October 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.70</p> |
| |
| <p><strong>Low: Security Manager Bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6796" rel="nofollow">CVE-2016-6796</a></p> |
| |
| <p>A malicious web application was able to bypass a configured |
| SecurityManager via manipulation of the configuration parameters for the |
| JSP Servlet.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1758495">1758495</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1763236">1763236</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 27 |
| December 2015 and made public on 27 October 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.70</p> |
| |
| <p><strong>Low: System Property Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6794" rel="nofollow">CVE-2016-6794</a></p> |
| |
| <p>When a SecurityManager is configured, a web application's ability to read |
| system properties should be controlled by the SecurityManager. Tomcat's |
| system property replacement feature for configuration files could be used |
| by a malicious web application to bypass the SecurityManager and read |
| system properties that should not be visible.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1754728">1754728</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 27 |
| December 2015 and made public on 27 October 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.70</p> |
| |
| <p><strong>Low: Security Manager Bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5018" rel="nofollow">CVE-2016-5018</a></p> |
| |
| <p>A malicious web application was able to bypass a configured |
| SecurityManager via a Tomcat utility method that was accessible to web |
| applications.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1754902">1754902</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1760309">1760309</a>.</p> |
| |
| <p>This issue was discovered by Alvaro Munoz and Alexander Mirosh of the HP |
| Enterprise Security Team and reported to the Apache Tomcat Security Team |
| on 5 July 2016. It was made public on 27 October 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.70</p> |
| |
| <p><strong>Low: Timing Attack</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0762" rel="nofollow">CVE-2016-0762</a></p> |
| |
| <p>The Realm implementations did not process the supplied password if the |
| supplied user name did not exist. This made a timing attack possible to |
| determine valid user names. Note that the default configuration includes |
| the LockOutRealm which makes exploitation of this vulnerability |
| harder.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1758502">1758502</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat Security Team on 1 January |
| 2016 and made public on 27 October 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.70</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.70"><span class="pull-right">20 June 2016</span> Fixed in Apache Tomcat 7.0.70</h3><div class="text"> |
| |
| <p><strong>Moderate: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092" rel="nofollow">CVE-2016-3092</a></p> |
| |
| <p>Apache Tomcat uses a package renamed copy of Apache Commons FileUpload to |
| implement the file upload requirements of the Servlet specification. A |
| denial of service vulnerability was identified in Commons FileUpload that |
| occurred when the length of the multipart boundary was just below the |
| size of the buffer (4096 bytes) used to read the uploaded file. This |
| caused the file upload process to take several orders of magnitude |
| longer than if the boundary was the typical tens of bytes long.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1743742">1743742</a>.</p> |
| |
| <p>This issue was identified by the TERASOLUNA Framework Development Team |
| and reported to the Apache Commons team via JPCERT on 9 May 2016. It was |
| made public on 21 June 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.69</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.68"><span class="pull-right">16 February 2016</span> Fixed in Apache Tomcat 7.0.68</h3><div class="text"> |
| |
| <p><strong>Low: Directory disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5345" rel="nofollow">CVE-2015-5345</a></p> |
| |
| <p>When accessing a directory protected by a security constraint with a URL |
| that did not end in a slash, Tomcat would redirect to the URL with the |
| trailing slash thereby confirming the presence of the directory before |
| processing the security constraint. It was therefore possible for a user |
| to determine if a directory existed or not, even if the user was not |
| permitted to view the directory. The issue also occurred at the root of a |
| web application in which case the presence of the web application was |
| confirmed, even if a user did not have access.</p> |
| |
| <p>The solution was to implement the redirect in the DefaultServlet so that |
| any security constraints and/or security enforcing Filters were processed |
| before the redirect. The Tomcat team recognised that moving the redirect |
| could cause regressions so two new Context configuration options |
| (<code>mapperContextRootRedirectEnabled</code> and |
| <code>mapperDirectoryRedirectEnabled</code>) were introduced. The initial |
| default was <code>false</code> for both since this was more secure. |
| However, due to regressions such as |
| <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=58765">Bug |
| 58765</a> the default for <code>mapperContextRootRedirectEnabled</code> |
| was later changed to true since it was viewed that the regression was |
| more serious than the security risk associated with being able to |
| determine if a web application was deployed at a given path.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1715213">1715213</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1716860">1716860</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1717212">1717212</a>.</p> |
| |
| <p>This issue was identified by Mark Koek of QCSec on 12 October 2015 and |
| made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.67</p> |
| |
| <p><strong>Moderate: CSRF token leak</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5351" rel="nofollow">CVE-2015-5351</a></p> |
| |
| <p>The index page of the Manager and Host Manager applications included a |
| valid CSRF token when issuing a redirect as a result of an |
| unauthenticated request to the root of the web application. If an |
| attacker had access to the Manager or Host Manager applications |
| (typically these applications are only accessible to internal users, not |
| exposed to the Internet), this token could then be used by the attacker |
| to construct a CSRF attack.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1720661">1720661</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1720663">1720663</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 8 December 2015 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.1 to 7.0.67</p> |
| |
| <p><strong>Low: Security Manager bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0706" rel="nofollow">CVE-2016-0706</a></p> |
| |
| <p>This issue only affects users running untrusted web applications under a |
| security manager.</p> |
| |
| <p>The internal StatusManagerServlet could be loaded by a malicious web |
| application when a security manager was configured. This servlet could |
| then provide the malicious web application with a list of all deployed |
| applications and a list of the HTTP request lines for all requests |
| currently being processed. This could have exposed sensitive information |
| from other web applications, such as session IDs, to the web |
| application.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1722801">1722801</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 27 December 2015 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.67</p> |
| |
| <p><strong>Moderate: Security Manager bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0714" rel="nofollow">CVE-2016-0714</a></p> |
| |
| <p>This issue only affects users running untrusted web applications under a |
| security manager.</p> |
| |
| <p>Tomcat provides several session persistence mechanisms. The |
| <code>StandardManager</code> persists session over a restart. The |
| <code>PersistentManager</code> is able to persist sessions to files, a |
| database or a custom <code>Store</code>. The cluster implementation |
| persists sessions to one or more additional nodes in the cluster. All of |
| these mechanisms could be exploited to bypass a security manager. Session |
| persistence is performed by Tomcat code with the permissions assigned to |
| Tomcat internal code. By placing a carefully crafted object into a |
| session, a malicious web application could trigger the execution of |
| arbitrary code.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1726923">1726923</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1727034">1727034</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 12 November 2015 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.67</p> |
| |
| <p><strong>Moderate: Security Manager bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0763" rel="nofollow">CVE-2016-0763</a></p> |
| |
| <p>This issue only affects users running untrusted web applications under a |
| security manager.</p> |
| |
| <p><code>ResourceLinkFactory.setGlobalContext()</code> is a public method |
| and was accessible to web applications even when running under a security |
| manager. This allowed a malicious web application to inject a malicious |
| global context that could in turn be used to disrupt other web |
| applications and/or read and write data owned by other web |
| applications.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1725931">1725931</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 18 January 2016 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.67</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.67"><span class="pull-right">10 December 2015</span> Fixed in Apache Tomcat 7.0.67</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.66 but the |
| release vote for the 7.0.66 release candidate did not pass. Therefore, |
| although users must download 7.0.67 to obtain a version that includes a |
| fix for this issue, version 7.0.66 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Low: Session Fixation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5346" rel="nofollow">CVE-2015-5346</a></p> |
| |
| <p>When recycling the <code>Request</code> object to use for a new request, |
| the <code>requestedSessionSSL</code> field was not recycled. This meant that |
| a session ID provided in the next request to be processed using the recycled |
| <code>Request</code> object could be used when it should not have been. This |
| gave the client the ability to control the session ID. In theory, this could |
| have been used as part of a session fixation attack but it would have been |
| hard to achieve as the attacker would not have been able to force the victim |
| to use the 'correct' <code>Request</code> object. It was also necessary for |
| at least one web application to be configured to use the SSL session ID as |
| the HTTP session ID. This is not a common configuration.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1713187">1713187</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 22 June 2014 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.5 to 7.0.65</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.65"><span class="pull-right">19 October 2015</span> Fixed in Apache Tomcat 7.0.65</h3><div class="text"> |
| |
| <p><strong>Low: Limited directory traversal</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5174" rel="nofollow">CVE-2015-5174</a></p> |
| |
| <p>This issue only affects users running untrusted web applications under a |
| security manager.</p> |
| |
| <p>When accessing resources via the <code>ServletContext</code> methods |
| <code>getResource()</code> <code>getResourceAsStream()</code> and |
| <code>getResourcePaths()</code> the paths should be limited to the |
| current web application. The validation was not correct and paths of the |
| form <code>"/.."</code> were not rejected. Note that paths starting with |
| <code>"/../"</code> were correctly rejected. This bug allowed malicious |
| web applications running under a security manager to obtain a directory |
| listing for the directory in which the web application had been deployed. |
| This should not be possible when running under a security manager. |
| Typically, the directory listing that would be exposed would be for |
| <code>$CATALINA_BASE/webapps.</code></p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1696284">1696284</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1700898">1700898</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 12 August 2015 |
| and made public on 22 February 2016.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.64</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.59"><span class="pull-right">4 February 2015</span> Fixed in Apache Tomcat 7.0.59</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.58 but the |
| release vote for the 7.0.58 release candidate did not pass. Therefore, |
| although users must download 7.0.59 to obtain a version that includes a |
| fix for this issue, versions 7.0.58 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Moderate: Security Manager bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7810" rel="nofollow">CVE-2014-7810</a></p> |
| |
| <p>Malicious web applications could use expression language to bypass the |
| protections of a Security Manager as expressions were evaluated within a |
| privileged code section.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1644019">1644019</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1645644">1645644</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 2 November 2014 |
| and made public on 14 May 2015.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.57</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.55"><span class="pull-right">27 July 2014</span> Fixed in Apache Tomcat 7.0.55</h3><div class="text"> |
| |
| <p><strong>Important: Request Smuggling</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0227" rel="nofollow">CVE-2014-0227</a></p> |
| |
| <p>It was possible to craft a malformed chunk as part of a chunked request |
| that caused Tomcat to read part of the request body as a new request.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1601333">1601333</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 30 May 2014 |
| and made public on 9 February 2015.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.54</p> |
| |
| <p><strong>Low: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0230" rel="nofollow">CVE-2014-0230</a></p> |
| |
| <p>When a response for a request with a request body is returned to the user |
| agent before the request body is fully read, by default Tomcat swallows the |
| remaining request body so that the next request on the connection may be |
| processed. There was no limit to the size of request body that Tomcat would |
| swallow. This permitted a limited Denial of Service as Tomcat would never |
| close the connection and a processing thread would remain allocated to the |
| connection.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1603781">1603781</a> |
| and improved in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1603811">1603811</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1609176">1609176</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1659295">1659295</a>.</p> |
| |
| <p>This issue was disclosed to the Tomcat security team by AntBean@secdig |
| from the Baidu Security Team on 4 June 2014 and made public on 9 April |
| 2015.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.54</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.54"><span class="pull-right">released 22 May 2014</span> Fixed in Apache Tomcat 7.0.54</h3><div class="text"> |
| |
| <p><strong>Low: Information Disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0119" rel="nofollow">CVE-2014-0119</a></p> |
| |
| <p>In limited circumstances it was possible for a malicious web application |
| to replace the XML parsers used by Tomcat to process XSLTs for the |
| default servlet, JSP documents, tag library descriptors (TLDs) and tag |
| plugin configuration files. The injected XML parser(s) could then bypass |
| the limits imposed on XML external entities and/or have visibility of the |
| XML files processed for other web applications deployed on the same |
| Tomcat instance.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1588199">1588199</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1589997">1589997</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1590028">1590028</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1590036">1590036</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 12 April 2014 |
| and made public on 27 May 2014.</p> |
| |
| <p>Affects: 7.0.0-7.0.53</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.53"><span class="pull-right">released 30 Mar 2014</span> Fixed in Apache Tomcat 7.0.53</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0075" rel="nofollow">CVE-2014-0075</a></p> |
| |
| <p>It was possible to craft a malformed chunk size as part of a chucked |
| request that enabled an unlimited amount of data to be streamed to the |
| server, bypassing the various size limits enforced on a request. This |
| enabled a denial of service attack.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1578341">1578341</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team by David Jorm of the |
| Red Hat Security Response Team on 28 February 2014 and made public on 27 |
| May 2014.</p> |
| |
| <p>Affects: 7.0.0-7.0.52</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0096" rel="nofollow">CVE-2014-0096</a></p> |
| |
| <p>The default servlet allows web applications to define (at multiple |
| levels) an XSLT to be used to format a directory listing. When running |
| under a security manager, the processing of these was not subject to the |
| same constraints as the web application. This enabled a malicious web |
| application to bypass the file access constraints imposed by the security |
| manager via the use of external XML entities.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1578637">1578637</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1578655">1578655</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 27 February 2014 |
| and made public on 27 May 2014.</p> |
| |
| <p>Affects: 7.0.0-7.0.52</p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0099" rel="nofollow">CVE-2014-0099</a></p> |
| |
| <p>The code used to parse the request content length header did not check |
| for overflow in the result. This exposed a request smuggling |
| vulnerability when Tomcat was located behind a reverse proxy that |
| correctly processed the content length header.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1578814">1578814</a>.</p> |
| |
| <p>A test case that demonstrated the parsing bug was sent to the Tomcat |
| security team on 13 March 2014 but no context was provided. The security |
| implications were identified by the Tomcat security team the day the |
| report was received and made public on 27 May 2014.</p> |
| |
| <p>Affects: 7.0.0-7.0.52</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.52"><span class="pull-right">released 17 Feb 2014</span> Fixed in Apache Tomcat 7.0.52</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.51 but the |
| release vote for the 7.0.51 release candidate did not pass. Therefore, |
| although users must download 7.0.52 to obtain a version that includes a |
| fix for this issue, version 7.0.51 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0050" rel="nofollow">CVE-2014-0050</a></p> |
| |
| <p>It was possible to craft a malformed Content-Type header for a multipart |
| request that caused Apache Tomcat to enter an infinite loop. A malicious |
| user could, therefore, craft a malformed request that triggered a denial |
| of service.</p> |
| |
| <p>The root cause of this error was a bug in Apache Commons FileUpload. |
| Tomcat 7 uses a packaged renamed copy of Apache Commons FileUpload to |
| implement the requirement of the Servlet 3.0 specification to support the |
| processing of mime-multipart requests. Tomcat 7 was therefore affected by |
| this issue.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1565169">1565169</a>.</p> |
| |
| <p>This issue was reported to the Apache Software Foundation on 04 Feb 2014 |
| and accidently made public on 06 Feb 2014.</p> |
| |
| <p>Affects: 7.0.0-7.0.50</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.50"><span class="pull-right">released 08 Jan 2014</span> Fixed in Apache Tomcat 7.0.50</h3><div class="text"> |
| |
| <p><i>Note: The issues below were fixed in Apache Tomcat 7.0.48 but the |
| release votes for 7.0.48 to 7.0.49 did not pass. |
| Therefore, although users must download 7.0.50 to obtain a version |
| that includes fixes for these issues, versions 7.0.48 to 7.0.49 are |
| not included in the list of affected versions.</i></p> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4322" rel="nofollow">CVE-2013-4322</a></p> |
| |
| <p>The fix for CVE-2012-3544 was not complete. It did not cover the |
| following cases:</p> |
| <ul> |
| <li>chunk extensions were not limited</li> |
| <li>whitespace after the : in a trailing header was not limited</li> |
| </ul> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1521864">1521864</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1549523">1549523</a>.</p> |
| |
| <p>The first part of this issue was identified by the Apache Tomcat security |
| team on 27 August 2013 and the second part by Saran Neti of TELUS |
| Security Labs on 5 November 2013. It was made public on 25 February 2014. |
| </p> |
| |
| <p>Affects: 7.0.0 to 7.0.47</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4590" rel="nofollow">CVE-2013-4590</a></p> |
| |
| <p>Application provided XML files such as web.xml, context.xml, *.tld, |
| *.tagx and *.jspx allowed XXE which could be used to expose Tomcat |
| internals to an attacker. This vulnerability only occurs when Tomcat is |
| running web applications from untrusted sources such as in a shared |
| hosting environment.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1549529">1549529</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat security team on 29 |
| October 2013 and made public on 25 February 2014.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.47</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.47"><span class="pull-right">released 24 Oct 2013</span> Fixed in Apache Tomcat 7.0.47</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.43 but the |
| release votes for 7.0.43 to 7.0.46 did not pass. |
| Therefore, although users must download 7.0.47 to obtain a version |
| that includes a fix for this issue, versions 7.0.43 to 7.0.46 are not |
| included in the list of affected versions.</i></p> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4286" rel="nofollow">CVE-2013-4286</a></p> |
| |
| <p>The fix for CVE-2005-2090 was not complete. It did not cover the |
| following cases:</p> |
| <ul> |
| <li>content-length header with chunked encoding over any HTTP connector |
| </li> |
| <li>multiple content-length headers over any AJP connector</li> |
| </ul> |
| |
| <p>Requests with multiple content-length headers or with a content-length |
| header when chunked encoding is being used should be rejected as invalid. |
| When multiple components (firewalls, caches, proxies and Tomcat) process |
| a sequence of requests where one or more requests contain either multiple |
| content-length headers or a content-length header when chunked encoding |
| is being used and several components do not reject the request and make |
| different decisions as to which content-length header to use an attacker |
| can poison a web-cache, perform an XSS attack and obtain sensitive |
| information from requests other then their own. Tomcat now rejects |
| requests with multiple content-length headers or with a content-length |
| header when chunked encoding is being used.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1521854">1521854</a>.</p> |
| |
| <p>This issue was identified by the Apache Tomcat security team on 15 August |
| 2013 and made public on 25 February 2014.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.42</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.40"><span class="pull-right">released 9 May 2013</span> Fixed in Apache Tomcat 7.0.40</h3><div class="text"> |
| |
| <p><strong>Moderate: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2071" rel="nofollow">CVE-2013-2071</a></p> |
| |
| <p>Bug <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=54178">54178</a> described a scenario where elements of a previous |
| request may be exposed to a current request. This was very difficult to |
| exploit deliberately but fairly likely to happen unexpectedly if an |
| application used AsyncListeners that threw RuntimeExceptions.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1471372">1471372</a>.</p> |
| |
| <p>The root cause of the problem was identified as a Tomcat bug on 2 April |
| 2013. The Tomcat security team identified the security implications on |
| 24 April 2013 and made those details public on 10 May 2013.</p> |
| |
| <p>Affects: 7.0.0-7.0.39</p> |
| |
| <p><strong>Important: Remote Code Execution</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4444" rel="nofollow">CVE-2013-4444</a></p> |
| |
| <p>In very limited circumstances, it was possible for an attacker to upload |
| a malicious JSP to a Tomcat server and then trigger the execution of that |
| JSP. While Remote Code Execution would normally be viewed as a critical |
| vulnerability, the circumstances under which this is possible are, in the |
| view of the Tomcat security team, sufficiently limited that this |
| vulnerability is viewed as important.</p> |
| |
| <p>For this attack to succeed all of the following requirements must be |
| met:</p> |
| |
| <ol> |
| <li>Using Oracle Java 1.7.0 update 25 or earlier (or any other Java |
| implementation where java.io.File is vulnerable to null byte |
| injection).</li> |
| <li>A web application must be deployed to a vulnerable version of |
| Tomcat.</li> |
| <li>The web application must use the Servlet 3.0 File Upload feature.</li> |
| <li>A file location within a deployed web application must be writeable by |
| the user the Tomcat process is running as. The Tomcat security |
| documentation recommends against this.</li> |
| <li>A custom listener for JMX connections (e.g. the JmxRemoteListener that |
| is not enabled by default) must be configured and be able to load |
| classes from Tomcat's common class loader (i.e. the custom JMX |
| listener must be placed in Tomcat's lib directory).</li> |
| <li>The custom JMX listener must be bound to an address other than |
| localhost for a remote attack (it is bound to localhost by default). |
| If the custom JMX listener is bound to localhost, a local attack will |
| still be possible.</li> |
| </ol> |
| |
| <p>Note that requirements 2 and 3 may be replaced with the following |
| requirement:</p> |
| |
| <ol start="7"> |
| <li>A web application is deployed that uses Apache Commons File Upload |
| 1.2.1 or earlier.</li> |
| </ol> |
| |
| <p>In this case (requirements 1, 4, 5, 6 and 7 met) a similar vulnerability |
| may exist on any Servlet container, not just Apache Tomcat.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1470437">1470437</a>.</p> |
| |
| <p>This issue was identified by Pierre Ernst of the VMware Security |
| Engineering, Communications and Response group (vSECR) and reported to |
| the Tomcat security team via the Pivotal security team on 5 September |
| 2014. It was made public on 10 September 2014.</p> |
| |
| <p>Affects: 7.0.0 to 7.0.39</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.33"><span class="pull-right">released 21 Nov 2012</span> Fixed in Apache Tomcat 7.0.33</h3><div class="text"> |
| |
| <p><strong>Important: Session fixation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2067" rel="nofollow">CVE-2013-2067</a></p> |
| |
| <p>FORM authentication associates the most recent request requiring |
| authentication with the current session. By repeatedly sending a request |
| for an authenticated resource while the victim is completing the login |
| form, an attacker could inject a request that would be executed using |
| the victim's credentials.</p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1408044">1408044</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 15 Oct 2012 and |
| made public on 10 May 2013.</p> |
| |
| <p>Affects: 7.0.0-7.0.32</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.32"><span class="pull-right">released 9 Oct 2012</span> Fixed in Apache Tomcat 7.0.32</h3><div class="text"> |
| |
| <p><strong>Important: Bypass of CSRF prevention filter</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4431" rel="nofollow">CVE-2012-4431</a></p> |
| |
| <p>The CSRF prevention filter could be bypassed if a request was made to a |
| protected resource without a session identifier present in the request. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1393088">1393088</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 8 September 2012 |
| and made public on 4 December 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.31</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.30"><span class="pull-right">released 6 Sep 2012</span> Fixed in Apache Tomcat 7.0.30</h3><div class="text"> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3544" rel="nofollow">CVE-2012-3544</a></p> |
| |
| <p>When processing a request submitted using the chunked transfer encoding, |
| Tomcat ignored but did not limit any extensions that were included. This |
| allows a client to perform a limited DOS by streaming an unlimited |
| amount of data to the server.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1378702">1378702</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1378921">1378921</a>.</p> |
| |
| <p>This issue was reported to the Tomcat security team on 10 November 2011 |
| and made public on 10 May 2013.</p> |
| |
| <p>Affects: 7.0.0-7.0.29</p> |
| |
| <p><strong>Moderate: DIGEST authentication weakness</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3439" rel="nofollow">CVE-2012-3439</a></p> |
| |
| <p>Three weaknesses in Tomcat's implementation of DIGEST authentication |
| were identified and resolved: |
| </p> |
| <ol> |
| <li>Tomcat tracked client rather than server nonces and nonce count.</li> |
| <li>When a session ID was present, authentication was bypassed.</li> |
| <li>The user name and password were not checked before when indicating |
| that a nonce was stale.</li> |
| </ol> |
| <p> |
| These issues reduced the security of DIGEST authentication making |
| replay attacks possible in some circumstances. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1377807">1377807</a>.</p> |
| |
| <p>The first issue was reported by Tilmann Kuhn to the Tomcat security team |
| on 19 July 2012. The second and third issues were discovered by the |
| Tomcat security team during the resulting code review. All three issues |
| were made public on 5 November 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.29</p> |
| |
| <p><strong>Important: Bypass of security constraints</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3546" rel="nofollow">CVE-2012-3546</a></p> |
| |
| <p>When using FORM authentication it was possible to bypass the security |
| constraint checks in the FORM authenticator by appending |
| <code>/j_security_check</code> to the end of the URL if some other |
| component (such as the Single-Sign-On valve) had called |
| <code>request.setUserPrincipal()</code> before the call to |
| <code>FormAuthenticator#authenticate()</code>. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1377892">1377892</a>.</p> |
| |
| <p>This issue was identified by the Tomcat security team on 13 July 2012 and |
| made public on 4 December 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.29</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.28"><span class="pull-right">released 19 Jun 2012</span> Fixed in Apache Tomcat 7.0.28</h3><div class="text"> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2733" rel="nofollow">CVE-2012-2733</a></p> |
| |
| <p>The checks that limited the permitted size of request headers were |
| implemented too late in the request parsing process for the HTTP NIO |
| connector. This enabled a malicious user to trigger an |
| OutOfMemoryError by sending a single request with very large headers. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1350301">1350301</a>.</p> |
| |
| <p>This was reported by Josh Spiewak to the Tomcat security team on 4 June |
| 2012 and made public on 5 November 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.27</p> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4534" rel="nofollow">CVE-2012-4534</a></p> |
| |
| <p>When using the NIO connector with sendfile and HTTPS enabled, if a client |
| breaks the connection while reading the response an infinite loop is |
| entered leading to a denial of service. This was originally reported as |
| <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=52858">bug |
| 52858</a>. |
| </p> |
| |
| <p>This was fixed in revision <a href="https://svn.apache.org/viewvc?view=rev&rev=1340218">1340218</a>.</p> |
| |
| <p>The security implications of this bug were reported to the Tomcat |
| security team by Arun Neelicattu of the Red Hat Security Response Team on |
| 3 October 2012 and made public on 4 December 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.27</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.23"><span class="pull-right">released 25 Nov 2011</span> Fixed in Apache Tomcat 7.0.23</h3><div class="text"> |
| |
| <p><strong>Important: Denial of service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0022" rel="nofollow">CVE-2012-0022</a></p> |
| |
| <p>Analysis of the recent hash collision vulnerability identified unrelated |
| inefficiencies with Apache Tomcat's handling of large numbers of |
| parameters and parameter values. These inefficiencies could allow an |
| attacker, via a specially crafted request, to cause large amounts of CPU |
| to be used which in turn could create a denial of service. The issue was |
| addressed by modifying the Tomcat parameter handling code to efficiently |
| process large numbers of parameters and parameter values.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1189899">1189899</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1190372">1190372</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1190482">1190482</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1194917">1194917</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195225">1195225</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195226">1195226</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195537">1195537</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195909">1195909</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195944">1195944</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195951">1195951</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1195977">1195977</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1198641">1198641</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 21 October 2011 and |
| made public on 17 January 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.22</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.22"><span class="pull-right">released 1 Oct 2011</span> Fixed in Apache Tomcat 7.0.22</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3375" rel="nofollow">CVE-2011-3375</a></p> |
| |
| <p>For performance reasons, information parsed from a request is often |
| cached in two places: the internal request object and the internal |
| processor object. These objects are not recycled at exactly the same |
| time. When certain errors occur that needed to be added to the access |
| log, the access logging process triggers the re-population of the request |
| object after it has been recycled. However, the request object was not |
| recycled before being used for the next request. That lead to information |
| leakage (e.g. remote IP address, HTTP headers) from the previous request |
| to the next request. The issue was resolved be ensuring that the request |
| and response objects were recycled after being re-populated to generate |
| the necessary access log entries.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1176592">revision 1176592</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 22 September 2011 and |
| made public on 17 January 2012.</p> |
| |
| <p>Affects: 7.0.0-7.0.21</p> |
| |
| <p><strong>Low: Privilege Escalation</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3376" rel="nofollow">CVE-2011-3376</a></p> |
| |
| <p>This issue only affects environments running web applications that are |
| not trusted (e.g. shared hosting environments). The Servlets that |
| implement the functionality of the Manager application that ships with |
| Apache Tomcat should only be available to Contexts (web applications) |
| that are marked as privileged. However, this check was not being made. |
| This allowed an untrusted web application to use the functionality of the |
| Manager application. This could be used to obtain information on running |
| web applications as well as deploying additional web applications. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1176588">revision 1176588</a>.</p> |
| |
| <p>This was identified by Ate Douma on 27 September 2011 and made public |
| on 8 November 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.21</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.21"><span class="pull-right">released 1 Sep 2011</span> Fixed in Apache Tomcat 7.0.21</h3><div class="text"> |
| |
| <p><strong>Important: Authentication bypass and information disclosure |
| </strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3190" rel="nofollow">CVE-2011-3190</a></p> |
| |
| <p>Apache Tomcat supports the AJP protocol which is used with reverse |
| proxies to pass requests and associated data about the request from the |
| reverse proxy to Tomcat. The AJP protocol is designed so that when a |
| request includes a request body, an unsolicited AJP message is sent to |
| Tomcat that includes the first part (or possibly all) of the request |
| body. In certain circumstances, Tomcat did not process this message as a |
| request body but as a new request. This permitted an attacker to have |
| full control over the AJP message permitting authentication bypass and |
| information disclosure. This vulnerability only occurs when all of the |
| following are true: |
| </p> |
| <ul> |
| <li>The org.apache.jk.server.JkCoyoteHandler AJP connector is not used |
| </li> |
| <li>POST requests are accepted</li> |
| <li>The request body is not processed</li> |
| </ul> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1162958">revision 1162958</a>.</p> |
| |
| <p>This was reported publicly on 20th August 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.20</p> |
| |
| <p>Mitigation options:</p> |
| <ul> |
| <li>Upgrade to Tomcat 7.0.21</li> |
| <li>Apply the appropriate <a href="https://svn.apache.org/viewvc?view=rev&rev=1162958">patch</a></li> |
| <li>Configure both Tomcat and the reverse proxy to use a shared secret.<br> |
| (It is "<code>requiredSecret</code>" attribute in AJP <Connector>, |
| "<code>worker.<i>workername</i>.secret</code>" directive for mod_jk. |
| The mod_proxy_ajp module currently does not support shared secrets).</li> |
| </ul> |
| |
| <p>References:</p> |
| <ul> |
| <li><a href="/tomcat-7.0-doc/config/ajp.html">AJP Connector documentation (Tomcat 7.0)</a></li> |
| <li><a href="/connectors-doc/reference/workers.html">workers.properties configuration (mod_jk)</a></li> |
| </ul> |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.20"><span class="pull-right">released 11 Aug 2011</span> Fixed in Apache Tomcat 7.0.20</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2729" rel="nofollow">CVE-2011-2729</a></p> |
| |
| <p>Due to a bug in the capabilities code, jsvc (the service wrapper for |
| Linux that is part of the Commons Daemon project) does not drop |
| capabilities allowing the application to access files and directories |
| owned by superuser. This vulnerability only occurs when all of the |
| following are true: |
| </p> |
| <ul> |
| <li>Tomcat is running on a Linux operating system</li> |
| <li>jsvc was compiled with libcap</li> |
| <li>-user parameter is used</li> |
| </ul> |
| <p> |
| Affected Tomcat versions shipped with source files for jsvc that included |
| this vulnerability. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1153379">revision 1153379</a>.</p> |
| |
| <p>This was identified by Wilfried Weissmann on 20 July 2011 and made public |
| on 12 August 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.19</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.19"><span class="pull-right">released 19 Jul 2011</span> Fixed in Apache Tomcat 7.0.19</h3><div class="text"> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2526" rel="nofollow">CVE-2011-2526</a></p> |
| |
| <p>Tomcat provides support for sendfile with the HTTP NIO and HTTP APR |
| connectors. sendfile is used automatically for content served via the |
| DefaultServlet and deployed web applications may use it directly via |
| setting request attributes. These request attributes were not validated. |
| When running under a security manager, this lack of validation allowed a |
| malicious web application to do one or more of the following that would |
| normally be prevented by a security manager: |
| </p> |
| <ul> |
| <li>return files to users that the security manager should make |
| inaccessible</li> |
| <li>terminate (via a crash) the JVM</li> |
| </ul> |
| <p>Additionally, these vulnerabilities only occur when all of the following |
| are true:</p> |
| <ul> |
| <li>untrusted web applications are being used</li> |
| <li>the SecurityManager is used to limit the untrusted web applications |
| </li> |
| <li>the HTTP NIO or HTTP APR connector is used</li> |
| <li>sendfile is enabled for the connector (this is the default)</li> |
| </ul> |
| |
| <p>This was fixed in revisions |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1145383">1145383</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1145489">1145489</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1145571">1145571</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1145694">1145694</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1146005">1146005</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 7 July 2011 and |
| made public on 13 July 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.18</p> |
| |
| <p><i>Note: The issues below were fixed in Apache Tomcat 7.0.17 but the |
| release votes for the 7.0.17 and 7.0.18 release candidates did not pass. |
| Therefore, although users must download 7.0.19 to obtain a version that |
| includes a fix for these issues, versions 7.0.17 and 7.0.18 are not |
| included in the list of affected versions.</i></p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2204" rel="nofollow">CVE-2011-2204</a></p> |
| |
| <p>When using the MemoryUserDatabase (based on tomcat-users.xml) and |
| creating users via JMX, an exception during the user creation process may |
| trigger an error message in the JMX client that includes the user's |
| password. This error message is also written to the Tomcat logs. User |
| passwords are visible to administrators with JMX access and/or |
| administrators with read access to the tomcat-users.xml file. Users that |
| do not have these permissions but are able to read log files may be able |
| to discover a user's password.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1140070">revision 1140070</a>.</p> |
| |
| <p>This was identified by Polina Genova on 14 June 2011 and |
| made public on 27 June 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.16</p> |
| |
| <p><strong>Low: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2481" rel="nofollow">CVE-2011-2481</a></p> |
| |
| <p>The re-factoring of XML validation for Tomcat 7.0.x re-introduced the |
| vulnerability previously reported as <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0783" rel="nofollow">CVE-2009-0783</a>. |
| This was initially |
| <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=51395"> |
| reported</a> as a memory leak. If a web application is the first web |
| application loaded, this bugs allows that web application to potentially |
| view and/or alter the web.xml, context.xml and tld files of other web |
| applications deployed on the Tomcat instance.</p> |
| |
| <p>This was first fixed in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1137753">revision 1137753</a>, |
| but reverted in <a href="https://svn.apache.org/viewvc?view=rev&rev=1138776">revision 1138776</a> and |
| finally fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1138788">revision 1138788</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 20 June 2011 and |
| made public on 12 August 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.16</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.14"><span class="pull-right">released 12 May 2011</span> Fixed in Apache Tomcat 7.0.14</h3><div class="text"> |
| |
| <p><strong>Important: Security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1582" rel="nofollow">CVE-2011-1582</a></p> |
| |
| <p>An error in the fixes for CVE-2011-1088/CVE-2011-1183 meant that security |
| constraints configured via annotations were ignored on the first request |
| to a Servlet. Subsequent requests were secured correctly.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1100832">revision 1100832</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 13 April 2011 and |
| made public on 17 May 2011.</p> |
| |
| <p>Affects: 7.0.12-7.0.13</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.12"><span class="pull-right">released 6 Apr 2011</span> Fixed in Apache Tomcat 7.0.12</h3><div class="text"> |
| |
| <p><strong>Important: Information disclosure</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1475" rel="nofollow">CVE-2011-1475</a></p> |
| |
| <p>Changes introduced to the HTTP BIO connector to support Servlet 3.0 |
| asynchronous requests did not fully account for HTTP pipelining. As a |
| result, when using HTTP pipelining a range of unexpected behaviours |
| occurred including the mixing up of responses between requests. While |
| the mix-up in responses was only observed between requests from the same |
| user, a mix-up of responses for requests from different users may also be |
| possible.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1086349">1086349</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1086352">1086352</a>. |
| (Note: HTTP pipelined requests are still likely to fail with the |
| HTTP BIO connector but will do so in a secure manner.)</p> |
| |
| <p>This was reported publicly on the Tomcat Bugzilla issue tracker on 22 Mar |
| 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.11</p> |
| |
| <p><strong>Moderate: Multiple weaknesses in HTTP DIGEST authentication</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" rel="nofollow">CVE-2011-1184</a></p> |
| |
| <p>Note: Mitre elected to break this issue down into multiple issues and |
| have allocated the following additional references to parts of this |
| issue: |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5062" rel="nofollow">CVE-2011-5062</a>, |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5063" rel="nofollow">CVE-2011-5063</a> and |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-5064" rel="nofollow">CVE-2011-5064</a>. The Apache Tomcat security team will |
| continue to treat this as a single issue using the reference |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1184" rel="nofollow">CVE-2011-1184</a>.</p> |
| |
| <p>The implementation of HTTP DIGEST authentication was discovered to have |
| several weaknesses: |
| </p> |
| <ul> |
| <li>replay attacks were permitted</li> |
| <li>server nonces were not checked</li> |
| <li>client nonce counts were not checked</li> |
| <li>qop values were not checked</li> |
| <li>realm values were not checked</li> |
| <li>the server secret was hard-coded to a known string</li> |
| </ul> |
| <p> |
| The result of these weaknesses is that DIGEST authentication was only as |
| secure as BASIC authentication. |
| </p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1087655">revision 1087655</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 16 March 2011 and |
| made public on 26 September 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.11</p> |
| |
| <p><strong>Important: Security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1183" rel="nofollow">CVE-2011-1183</a></p> |
| |
| <p>A regression in the fix for CVE-2011-1088 meant that security constraints |
| were ignored when no login configuration was present in the web.xml and |
| the web application was marked as meta-data complete.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1087643">revision 1087643</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 17 March 2011 and |
| made public on 6 April 2011.</p> |
| |
| <p>Affects: 7.0.11</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.11"><span class="pull-right">released 11 Mar 2011</span> Fixed in Apache Tomcat 7.0.11</h3><div class="text"> |
| |
| <p><strong>Important: Security constraint bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1088" rel="nofollow">CVE-2011-1088</a></p> |
| |
| <p>When a web application was started, <code>ServletSecurity</code> |
| annotations were ignored. This meant that some areas of the application |
| may not have been protected as expected. This was partially fixed in |
| Apache Tomcat 7.0.10 and fully fixed in 7.0.11.</p> |
| |
| <p>This was fixed in revisions <a href="https://svn.apache.org/viewvc?view=rev&rev=1076586">1076586</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1076587">1076587</a>, |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1077995">1077995</a> and |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1079752">1079752</a>.</p> |
| |
| <p>This was reported publicly on the Tomcat users mailing list on 2 Mar |
| 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.10</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.8"><span class="pull-right">released 5 Feb 2011</span> Fixed in Apache Tomcat 7.0.8</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.7 but the |
| release vote for the 7.0.7 release candidate did not pass. Therefore, |
| although users must download 7.0.8 to obtain a version that includes a |
| fix for this issue, version 7.0.7 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Important: Remote Denial Of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0534" rel="nofollow">CVE-2011-0534</a></p> |
| |
| <p>The NIO connector expands its buffer endlessly during request line |
| processing. That behaviour can be used for a denial of service attack |
| using a carefully crafted request.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1065939">revision 1065939</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 27 Jan 2011 and |
| made public on 5 Feb 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.6</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.6"><span class="pull-right">released 14 Jan 2011</span> Fixed in Apache Tomcat 7.0.6</h3><div class="text"> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0013" rel="nofollow">CVE-2011-0013</a></p> |
| |
| <p>The HTML Manager interface displayed web application provided data, such |
| as display names, without filtering. A malicious web application could |
| trigger script execution by an administrative user when viewing the |
| manager pages.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1057279">revision 1057279</a>.</p> |
| |
| <p>This was identified by the Tomcat security team on 12 Nov 2010 and |
| made public on 5 Feb 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.5</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.5"><span class="pull-right">released 1 Dec 2010</span> Fixed in Apache Tomcat 7.0.5</h3><div class="text"> |
| |
| <p><strong>Low: Cross-site scripting</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4172" rel="nofollow">CVE-2010-4172</a></p> |
| |
| <p>The Manager application used the user provided parameters sort and |
| orderBy directly without filtering thereby permitting cross-site |
| scripting. The CSRF protection, which is enabled by default, prevents an |
| attacker from exploiting this.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1037778">revision 1037778</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 15 Nov 2010 and |
| made public on 22 Nov 2010.</p> |
| |
| <p>Affects: 7.0.0-7.0.4</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.4"><span class="pull-right">released 21 Oct 2010</span> Fixed in Apache Tomcat 7.0.4</h3><div class="text"> |
| |
| <p><strong>Low: SecurityManager file permission bypass</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3718" rel="nofollow">CVE-2010-3718</a></p> |
| |
| <p>When running under a SecurityManager, access to the file system is |
| limited but web applications are granted read/write permissions to the |
| work directory. This directory is used for a variety of temporary files |
| such as the intermediate files generated when compiling JSPs to Servlets. |
| The location of the work directory is specified by a ServletContect |
| attribute that is meant to be read-only to web applications. However, |
| due to a coding error, the read-only setting was not applied. Therefore, |
| a malicious web application may modify the attribute before Tomcat |
| applies the file permissions. This can be used to grant read/write |
| permissions to any area on the file system which a malicious web |
| application may then take advantage of. This vulnerability is only |
| applicable when hosting web applications from untrusted sources such as |
| shared hosting environments.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=1022134">revision 1022134</a>.</p> |
| |
| <p>This was discovered by the Tomcat security team on 12 Oct 2010 and |
| made public on 5 Feb 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.3</p> |
| |
| </div><h3 id="Fixed_in_Apache_Tomcat_7.0.2"><span class="pull-right">released 11 Aug 2010</span> Fixed in Apache Tomcat 7.0.2</h3><div class="text"> |
| |
| <p><i>Note: The issue below was fixed in Apache Tomcat 7.0.1 but the |
| release vote for the 7.0.1 release candidate did not pass. Therefore, |
| although users must download 7.0.2 to obtain a version that includes a |
| fix for this issue, version 7.0.2 is not included in the list of |
| affected versions.</i></p> |
| |
| <p><strong>Important: Remote Denial Of Service and Information Disclosure |
| Vulnerability</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2227" rel="nofollow">CVE-2010-2227</a></p> |
| |
| <p>Several flaws in the handling of the 'Transfer-Encoding' header were |
| found that prevented the recycling of a buffer. A remote attacker could |
| trigger this flaw which would cause subsequent requests to fail and/or |
| information to leak between requests. This flaw is mitigated if Tomcat is |
| behind a reverse proxy (such as Apache httpd 2.2) as the proxy should |
| reject the invalid transfer encoding header.</p> |
| |
| <p>This was fixed in <a href="https://svn.apache.org/viewvc?view=rev&rev=958911">revision 958911</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 14 Jun 2010 and |
| made public on 9 Jul 2010.</p> |
| |
| <p>Affects: 7.0.0</p> |
| |
| </div><h3 id="Not_a_vulnerability_in_Tomcat">Not a vulnerability in Tomcat</h3><div class="text"> |
| |
| <p><strong>Important: Denial of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6056" rel="nofollow">CVE-2017-6056</a></p> |
| |
| <p>In February 2015 a single user reported high CPU usage (<a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=57544">57544</a>) |
| which was traced to a tight loop. However, it was not clear how the |
| conditions necessary to enter the loop were being created. There was no |
| evidence that indicated that the loop was user triggerable. The only |
| potential paths identified by code inspection depended on application |
| bugs (retaining references to request objects and accessing after the |
| request had completed).</p> |
| |
| <p>It was (and still is) believed that an application bug was the most |
| likely root cause. Therefore, <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=57544">57544</a> was not treated as a DoS |
| vulnerability.</p> |
| |
| <p>In November 2016, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816" rel="nofollow">CVE-2016-6816</a> was announced. When downstream |
| distributions, notably Debian, back-ported the fix for |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816" rel="nofollow">CVE-2016-6816</a> they inadvertently make it trivial for users to |
| trigger the tight loop from <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=57544">57544</a>. This made a DoS attack |
| trivial to mount and resulted in multiple reports of problems including |
| <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=60578">60578</a> and <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=60581">60581</a>.</p> |
| |
| <p>Tomcat releases from the Apache Software Foundation were not affected as |
| the ASF did not release any versions that contained the fix for |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816" rel="nofollow">CVE-2016-6816</a> but not the fix for <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=57544">57544</a>.</p> |
| |
| <p>This issue was first announced on 13 February 2017.</p> |
| |
| <p>Affects: Debian, Ubuntu and potentially other downstream |
| distributions.</p> |
| |
| <p><strong>Low: Denial Of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5568" rel="nofollow">CVE-2012-5568</a></p> |
| |
| <p>Sending an HTTP request 1 byte at a time will consume a thread from the |
| connection pool until the request has been fully processed if using the |
| BIO or APR/native HTTP connectors. Multiple requests may be used to |
| consume all threads in the connection pool thereby creating a denial of |
| service.</p> |
| |
| <p>Since the relationship between the client side resources and server side |
| resources is a linear one, this issue is not something that the Tomcat |
| Security Team views as a vulnerability. This is a generic DoS problem and |
| there is no magic solution. This issue has been discussed several times |
| on the Tomcat mailing lists. The best place to start to review these |
| discussions is the report for |
| <a href="https://bz.apache.org/bugzilla/show_bug.cgi?id=54263">bug |
| 54236</a>.</p> |
| |
| <p>This was first discussed on the public Tomcat users mailing list on 19 |
| June 2009.</p> |
| |
| <p>Affects: 7.0.0-7.0.x</p> |
| |
| <p><strong>Important: Remote Denial Of Service</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4476" rel="nofollow">CVE-2010-4476</a></p> |
| |
| <p>A JVM bug could cause Double conversion to hang JVM when accessing to a |
| form based security constrained page or any page that calls |
| javax.servlet.ServletRequest.getLocale() or |
| javax.servlet.ServletRequest.getLocales(). A specially crafted request |
| can be used to trigger a denial of service. |
| </p> |
| |
| <p>A work-around for this JVM bug was provided in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=1066244">revision 1066244</a>.</p> |
| |
| <p>This was first reported to the Tomcat security team on 01 Feb 2011 and |
| made public on 31 Jan 2011.</p> |
| |
| <p>Affects: 7.0.0-7.0.6</p> |
| |
| <p><strong>Moderate: TLS SSL Man In The Middle</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555" rel="nofollow">CVE-2009-3555</a></p> |
| |
| <p>A vulnerability exists in the TLS protocol that allows an attacker to |
| inject arbitrary requests into an TLS stream during renegotiation.</p> |
| |
| <p>The TLS implementation used by Tomcat varies with connector. The blocking |
| IO (BIO) and non-blocking (NIO) connectors use the JSSE implementation |
| provided by the JVM. The APR/native connector uses OpenSSL.</p> |
| |
| <p>The BIO connector is vulnerable if the JSSE version used is vulnerable. |
| To workaround a vulnerable version of JSSE, use the connector attribute |
| <code>allowUnsafeLegacyRenegotiation</code>. It should be set to |
| <code>false</code> (the default) to protect against this vulnerability. |
| </p> |
| |
| <p>The NIO connector prior to 7.0.10 is not vulnerable as it does not |
| support renegotiation.</p> |
| |
| <p>The NIO connector is vulnerable from version 7.0.10 onwards if the JSSE |
| version used is vulnerable. To workaround a vulnerable version of JSSE, |
| use the connector attribute <code>allowUnsafeLegacyRenegotiation</code>. |
| It should be set to <code>false</code> (the default) to protect against |
| this vulnerability.</p> |
| |
| <p>The APR/native workarounds are detailed on the |
| <a href="security-native.html">APR/native connector security page</a>. |
| </p> |
| |
| <p>Users should be aware that the impact of disabling renegotiation will |
| vary with both application and client. In some circumstances disabling |
| renegotiation may result in some clients being unable to access the |
| application.</p> |
| |
| <p>This was worked-around in |
| <a href="https://svn.apache.org/viewvc?view=rev&rev=882320">revision 891292</a>.</p> |
| |
| <p>Support for the new TLS renegotiation protocol (RFC 5746) that does not |
| have this security issue:</p> |
| |
| <ul> |
| <li>For connectors using JSSE implementation provided by JVM: |
| Added in Tomcat 7.0.8.<br> |
| Requires JRE that supports RFC 5746. For Oracle JRE that is |
| <a href="http://www.oracle.com/technetwork/java/javase/documentation/tlsreadme2-176330.html" rel="nofollow">known</a> |
| to be 6u22 or later. |
| </li> |
| <li>For connectors using APR and OpenSSL:<br> |
| TBD. See |
| <a href="security-native.html">APR/native connector security page</a>. |
| </li> |
| </ul> |
| |
| <p><strong>Important: Remote Memory Read</strong> |
| <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160" rel="nofollow">CVE-2014-0160</a> (a.k.a. "Heartbleed")</p> |
| |
| <p>A bug in certain versions of <a href="www.openssl.org">OpenSSL</a> |
| can allow an unauthenticated remote user to read certain contents of |
| the server's memory. Binary versions of tcnative 1.1.24 - 1.1.29 |
| include this vulnerable version of OpenSSL. tcnative 1.1.30 and later |
| ship with patched versions of OpenSSL.</p> |
| |
| <p>This issue was first announced on 7 April 2014.</p> |
| |
| <p>Affects: OpenSSL 1.0.1-1.0.1f, tcnative 1.1.24-1.1.29</p> |
| |
| </div></div></div></div></main><footer id="footer"> |
| Copyright © 1999-2026, The Apache Software Foundation |
| <br> |
| Apache Tomcat, Tomcat, Apache, the Apache Tomcat logo and the Apache logo |
| are either registered trademarks or trademarks of the Apache Software |
| Foundation. |
| </footer></div><script src="res/js/tomcat.js"></script></body></html> |