VDB

RHSA-2018%3A2470

RHSA-2018%3A2470 PUBLISHED CVSS 5.699999809265137 MEDIUM

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

Risk Scores

CVSS 3.0
5.699999809265137
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Web Server 3.1

Timeline

  • Aug 16, 2018 CVE Published
  • Mar 19, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory

References

…and 4 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›