CVE-2018-1304
Last modified
CVE-2018-1304 is a vulnerability of currently unknown severity. The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. EPSS estimates a 17.72% chance of exploitation in the next 30 days.
Description
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Apache | Tomcat | >= 7.0.0, <= 7.0.84 | — |
| Apache | Tomcat | >= 8.0.0, <= 8.0.49 | — |
| Apache | Tomcat | >= 8.5.0, <= 8.5.27 | — |
| Apache | Tomcat | >= 9.0.0, <= 9.0.4 | — |
| Apache | Tomcat | 8.0.0 | Rc1 |
| Apache | Tomcat | 9.0.0 | Milestone1 |
| Redhat | Jboss Enterprise Application Platform | 6 | — |
| Redhat | Jboss Enterprise Application Platform | 6.4 | — |
| Redhat | Jboss Enterprise Web Server | 3.0.0 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 17.10 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Oracle | Fusion Middleware | 12.2.1.3.0 | — |
| Oracle | Hospitality Guest Access | 4.2.0 | — |
| Oracle | Hospitality Guest Access | 4.2.1 | — |
| Oracle | Micros Relate Crm Software | 11.4 | — |
| Oracle | Secure Global Desktop | 5.3 | — |
| Oracle | Secure Global Desktop | 5.4 | — |
| Redhat | Jboss Middleware | 1 | — |
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/103170Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040427Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1320Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1447Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1449Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00004.htmlIssue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00008.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00044.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180706-0001/Patch, Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4281Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/103170Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040427Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0465Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0466Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1320Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1447Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1448Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1449Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2939Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00004.htmlIssue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/06/msg00008.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00044.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180706-0001/Patch, Third Party Advisory
- https://usn.ubuntu.com/3665-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4281Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1304?
How severe is CVE-2018-1304?
How do I fix CVE-2018-1304?
Are you affected by CVE-2018-1304?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
