VDB
RHSA-2019:0450
RHSA-2019:0450
PUBLISHED
CVSS 5.699999809265137 MEDIUM
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Risk Scores
CVSS 3.0
5.699999809265137
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Web Server 5.0 |
Timeline
- Mar 4, 2019 CVE Published
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1579611 issue
- https://issues.redhat.com/browse/JWS-1069 advisory
- https://issues.redhat.com/browse/JWS-1070 advisory
- https://issues.redhat.com/browse/JWS-1071 advisory
- https://issues.redhat.com/browse/JWS-1074 advisory
- https://issues.redhat.com/browse/JWS-1080 advisory
- https://www.cve.org/CVERecord?id=CVE-2018-8014 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-8014 advisory
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.89 advisory
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.32 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-8034 advisory
- https://access.redhat.com/errata/RHSA-2019:0450 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1607580 issue
- https://issues.redhat.com/browse/JWS-1072 advisory
- https://issues.redhat.com/browse/JWS-1073 advisory
- https://issues.redhat.com/browse/JWS-1122 advisory
- https://issues.redhat.com/browse/JWS-1123 advisory
- https://issues.redhat.com/browse/JWS-1153 advisory
- https://issues.redhat.com/browse/JWS-1160 advisory
…and 11 more