Bug 1102379 - (CVE-2018-8034) VUL-0: CVE-2018-8034: tomcat: host name verification missing in WebSocket client
(CVE-2018-8034)
VUL-0: CVE-2018-8034: tomcat: host name verification missing in WebSocket client
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/211458/
CVSSv3:RedHat:CVE-2018-8034:4.3:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-07-24 09:27 UTC by Johannes Segitz
Modified: 2018-11-29 07:46 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2018-07-24 09:27:12 UTC
rh#1607580

Flaw affecting tomcat 8.0.0.RC1 to 8.0.52 and 9.0.0.M1 to 9.0.9 . The host name verification when using TLS with the WebSocket client was not enabled by default.

Upstream patch:
http://svn.apache.org/viewvc?view=revision&revision=1833757
http://svn.apache.org/viewvc?view=rev&rev=1833759

tomcat on 12 and 15 affected

References:
https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-9.html
https://bugzilla.redhat.com/show_bug.cgi?id=1607580
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8034
Comment 7 Swamp Workflow Management 2018-09-13 10:12:20 UTC
SUSE-SU-2018:2699-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1095472,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Server 12-SP3 (src):    tomcat-8.0.53-29.13.1
Comment 8 Swamp Workflow Management 2018-09-17 10:13:22 UTC
openSUSE-SU-2018:2740-1: An update that solves four vulnerabilities and has two fixes is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1095472,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
openSUSE Leap 42.3 (src):    tomcat-8.0.53-15.1
Comment 12 Swamp Workflow Management 2018-10-04 22:08:42 UTC
SUSE-SU-2018:3011-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Module for Web Scripting 15 (src):    tomcat-9.0.10-3.3.1
Comment 13 Swamp Workflow Management 2018-10-06 16:10:42 UTC
openSUSE-SU-2018:3054-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
openSUSE Leap 15.0 (src):    tomcat-9.0.10-lp150.2.3.2
Comment 15 Swamp Workflow Management 2018-10-19 19:09:23 UTC
SUSE-SU-2018:3261-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481,1093697,1102379,1102400,1110850
CVE References: CVE-2017-15706,CVE-2018-11784,CVE-2018-1304,CVE-2018-1305,CVE-2018-1336,CVE-2018-8014,CVE-2018-8034
Sources used:
SUSE Linux Enterprise Server 12-LTSS (src):    tomcat-7.0.90-7.23.1
Comment 16 Swamp Workflow Management 2018-10-24 16:46:49 UTC
SUSE-SU-2018:3388-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481,1093697,1102379,1102400,1102410,1110850
CVE References: CVE-2017-15706,CVE-2018-11784,CVE-2018-1304,CVE-2018-1305,CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    tomcat-8.0.53-10.35.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    tomcat-8.0.53-10.35.1
Comment 18 Marcus Meissner 2018-11-28 12:59:35 UTC
released
Comment 19 Swamp Workflow Management 2018-11-28 14:10:10 UTC
SUSE-SU-2018:3011-2: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1067720,1093697,1102379,1102400,1102410
CVE References: CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    tomcat-9.0.10-3.7.1