← All CVEs

CVE-2018-8014

critical · 9.8

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

9.8
CVSS
21.7%
EPSS (exploit prob.)
98th
EPSS percentile
2018-05-16
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-1188

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.41, <= 7.0.88
apachetomcat>= 8.0.0, <= 8.0.52
apachetomcat>= 8.5.0, <= 8.5.31
apachetomcat>= 9.0.0, <= 9.0.8
apachetomcat8.0.0
apachetomcat9.0.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
debiandebian_linux8.0
netapponcommand_insightall versions
netapponcommand_unified_manager>= 9.4
netapponcommand_workflow_automationall versions
netappsnapcenter_serverall versions
netappstorage_automation_storeall versions
netapponcommand_unified_manager>= 7.3
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8014