Back

HIGH

tomcat: Host name verification missing in WebSocket client

Published Aug 1, 2018

Description

The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

Affected products

Remediation

Red Hat statement

Tomcat 6, and Red Hat products shipping it, are not affected by this CVE. Tomcat 7, 8, and 9, as well as Red Hat Products shipping them, are affected. Affected products, including Red Hat JBoss Web Server 3 and 5, Enterprise Application Server 6, and Fuse 7, may provide fixes for this issue in a future release.

Metrics

References (68)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 1, 2018
Updated Oct 21, 2024
Reserved Mar 9, 2018
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 22, 2018
GHSA-46J3-R4PJ-4835