CVE-2018-1304
Last modified
CVE-2018-1304 is a vulnerability of currently unknown severity. The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. EPSS estimates a 17.72% chance of exploitation in the next 30 days.
Description
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Tomcat | >= 7.0.0, <= 7.0.84 | — |
| Apache | Tomcat | >= 8.0.0, <= 8.0.49 | — |
| Apache | Tomcat | >= 8.5.0, <= 8.5.27 | — |
| Apache | Tomcat | >= 9.0.0, <= 9.0.4 | — |
| Apache | Tomcat | 8.0.0 | Rc1 |
| Apache | Tomcat | 9.0.0 | Milestone1 |
| Redhat | Jboss Enterprise Application Platform | 6 | — |
| Redhat | Jboss Enterprise Application Platform | 6.4 | — |
| Redhat | Jboss Enterprise Web Server | 3.0.0 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 17.10 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Oracle | Fusion Middleware | 12.2.1.3.0 | — |
| Oracle | Hospitality Guest Access | 4.2.0 | — |
| Oracle | Hospitality Guest Access | 4.2.1 | — |
| Oracle | Micros Relate Crm Software | 11.4 | — |
| Oracle | Secure Global Desktop | 5.3 | — |
| Oracle | Secure Global Desktop | 5.4 | — |
| Redhat | Jboss Middleware | 1 | — |
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/103170Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040427Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1320Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1447Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1449Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00004.htmlIssue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00008.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00044.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180706-0001/Patch, Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4281Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/103170Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040427Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1320Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1447Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1449Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00004.htmlIssue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00008.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00044.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180706-0001/Patch, Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4281Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1304?
How severe is CVE-2018-1304?
How do I fix CVE-2018-1304?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-13032ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add s…
- CVE-2018-13033The Binary File Descriptor (BFD) library (aka libbfd), as di…
- CVE-2018-13034Directory traversal in Jester web framework 0.2.0 allows rem…
- CVE-2018-13037An issue was discovered in jpeg-compressor 0.1. The bmp_load…
- CVE-2018-13038OpenSID 18.06-pasca has an Unrestricted File Upload vulnerab…
- CVE-2018-13039OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS)…
- CVE-2018-13040OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerabi…
- CVE-2018-13041The mint function of a smart contract implementation for Lin…7.5
- CVE-2018-13042The 1Password application 6.8 for Android is affected by a D…
- CVE-2018-13043scripts/grep-excuses.pl in Debian devscripts through 2.18.3 …
- CVE-2018-13045SQL injection vulnerability in the "Bazar" page in Yeswiki C…
- CVE-2018-13049The constructSQL function in inc/search.class.php in GLPI 9.…
Are you affected by CVE-2018-1304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
