VDB
RHSA-2018%3A2470
RHSA-2018%3A2470
PUBLISHED
CVSS 5.699999809265137 MEDIUM
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Risk Scores
CVSS 3.0
5.699999809265137
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 3.1 |
Timeline
- Aug 16, 2018 CVE Published
- Mar 19, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2018:2470 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=webserver&downloadType=securityPatches&version=3.1 advisory
- https://access.redhat.com/documentation/en-us/red_hat_jboss_web_server/3.1/html-single/red_hat_jboss_web_server_3.1_service_pack_4_release_notes/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1579611 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1581569 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1583998 issue
- https://issues.redhat.com/browse/JWS-1042 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2018/rhsa-2018_2470.json advisory
- https://access.redhat.com/security/cve/CVE-2018-8014 advisory
- https://www.cve.org/CVERecord?id=CVE-2018-8014 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-8014 advisory
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.89 advisory
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.0.53 advisory
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.32 advisory
- http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.9 advisory
- https://access.redhat.com/security/cve/CVE-2018-8019 advisory
- https://www.cve.org/CVERecord?id=CVE-2018-8019 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-8019 advisory
- http://mail-archives.apache.org/mod_mbox/www-announce/201807.mbox/%3C20180721095943.GA24320%40minotaur.apache.org%3E advisory
…and 4 more