Bug 1082480 - (CVE-2018-1304) VUL-0: CVE-2018-1304: tomcat, tomcat6: Incorrect handling of empty string URL in security constraints can lead to unitended exposure of resources
(CVE-2018-1304)
VUL-0: CVE-2018-1304: tomcat, tomcat6: Incorrect handling of empty string URL...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Matei Albu
Security Team bot
https://smash.suse.de/issue/200728/
CVSSv3:SUSE:CVE-2018-1304:4.8:(AV:N/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-02-23 07:41 UTC by Alexander Bergmann
Modified: 2019-06-06 11:46 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2018-02-23 07:41:27 UTC
rh#1548289

Apache Tomcat versions 7.0.0 to 7.0.84, 8.0.0.RC1 to 8.0.49 and 8.5.0 to 8.5.27 does not properly handle the URL empty string ("") when used as part of a security constraint definition. This can lead to the security constraint being ignored, leading to unitended exposure of resources.


External References:

https://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.85
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.50
https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.28


Upstream Bug Report:

https://bz.apache.org/bugzilla/show_bug.cgi?id=62067


Upstream Fixes:

Tomcat 7.0.x:

http://svn.apache.org/viewvc?view=rev&rev=1823309

Tomcat 8.0.x:

http://svn.apache.org/viewvc?view=rev&rev=1814827

Tomcat 8.5.x:

http://svn.apache.org/viewvc?view=rev&rev=1823307

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1548289
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1304
http://seclists.org/oss-sec/2018/q1/175
Comment 1 Alexander Bergmann 2018-02-23 08:21:59 UTC
The correct Tomcat 8.0.x commit is:
http://svn.apache.org/viewvc?view=revision&revision=1823308
Comment 2 Swamp Workflow Management 2018-03-26 13:19:22 UTC
SUSE-SU-2018:0817-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481
CVE References: CVE-2017-15706,CVE-2018-1304,CVE-2018-1305
Sources used:
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    tomcat-8.0.50-29.8.2
SUSE Linux Enterprise Server 12-SP3 (src):    tomcat-8.0.50-29.8.2
SUSE Linux Enterprise Server 12-SP2 (src):    tomcat-8.0.50-29.8.2
Comment 3 Swamp Workflow Management 2018-03-29 22:08:05 UTC
openSUSE-SU-2018:0852-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481
CVE References: CVE-2017-15706,CVE-2018-1304,CVE-2018-1305
Sources used:
openSUSE Leap 42.3 (src):    tomcat-8.0.50-12.1
Comment 7 Swamp Workflow Management 2018-06-29 13:30:49 UTC
SUSE-SU-2018:1847-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1042910,1082480
CVE References: CVE-2017-5664,CVE-2018-1304
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    tomcat6-6.0.53-0.57.7.1
Comment 15 Swamp Workflow Management 2018-10-19 19:08:59 UTC
SUSE-SU-2018:3261-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481,1093697,1102379,1102400,1110850
CVE References: CVE-2017-15706,CVE-2018-11784,CVE-2018-1304,CVE-2018-1305,CVE-2018-1336,CVE-2018-8014,CVE-2018-8034
Sources used:
SUSE Linux Enterprise Server 12-LTSS (src):    tomcat-7.0.90-7.23.1
Comment 16 Swamp Workflow Management 2018-10-24 16:46:23 UTC
SUSE-SU-2018:3388-1: An update that fixes 8 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1078677,1082480,1082481,1093697,1102379,1102400,1102410,1110850
CVE References: CVE-2017-15706,CVE-2018-11784,CVE-2018-1304,CVE-2018-1305,CVE-2018-1336,CVE-2018-8014,CVE-2018-8034,CVE-2018-8037
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    tomcat-8.0.53-10.35.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    tomcat-8.0.53-10.35.1
Comment 17 Marcus Meissner 2019-06-06 11:46:10 UTC
done