← All CVEs

CVE-2018-8034

high · 7.5

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

7.5
CVSS
21.3%
EPSS (exploit prob.)
97th
EPSS percentile
2018-08-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-295

Affected products

VendorProductAffected versions
apachetomcat>= 7.0.35, <= 7.0.88
apachetomcat>= 8.0.0, <= 8.0.52
apachetomcat>= 8.5.0, <= 8.5.31
apachetomcat>= 9.0.1, <= 9.0.9
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat8.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0
apachetomcat9.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8034