Back

MEDIUM

tomcat: Late application of security constraints can lead to resource exposure for unauthorised users

Published Feb 23, 2018

Description

Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (68)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Feb 23, 2018
Updated Sep 17, 2024
Reserved Dec 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 23, 2018
GHSA-JX6H-3FJX-CGV5