{ "CVE_data_meta" : { "ASSIGNER" : "security@apache.org", "DATE_PUBLIC" : "2018-02-23T00:00:00", "ID" : "CVE-2018-1305", "STATE" : "PUBLIC" }, "affects" : { "vendor" : { "vendor_data" : [ { "product" : { "product_data" : [ { "product_name" : "Apache Tomcat", "version" : { "version_data" : [ { "version_value" : "Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.84" } ] } } ] }, "vendor_name" : "Apache Software Foundation" } ] } }, "data_format" : "MITRE", "data_type" : "CVE", "data_version" : "4.0", "description" : { "description_data" : [ { "lang" : "eng", "value" : "Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them." } ] }, "problemtype" : { "problemtype_data" : [ { "description" : [ { "lang" : "eng", "value" : "Information Disclosure" } ] } ] }, "references" : { "reference_data" : [ { "name" : "[debian-lts-announce] 20180306 [SECURITY] [DLA 1301-1] tomcat7 security update", "refsource" : "MLIST", "url" : "https://lists.debian.org/debian-lts-announce/2018/03/msg00004.html" }, { "name" : "https://lists.apache.org/thread.html/d3354bb0a4eda4acc0a66f3eb24a213fdb75d12c7d16060b23e65781@%3Cannounce.tomcat.apache.org%3E", "refsource" : "MISC", "url" : "https://lists.apache.org/thread.html/d3354bb0a4eda4acc0a66f3eb24a213fdb75d12c7d16060b23e65781@%3Cannounce.tomcat.apache.org%3E" }, { "name" : "RHSA-2018:0465", "refsource" : "REDHAT", "url" : "https://access.redhat.com/errata/RHSA-2018:0465" }, { "name" : "RHSA-2018:0466", "refsource" : "REDHAT", "url" : "https://access.redhat.com/errata/RHSA-2018:0466" }, { "name" : "103144", "refsource" : "BID", "url" : "http://www.securityfocus.com/bid/103144" }, { "name" : "1040428", "refsource" : "SECTRACK", "url" : "http://www.securitytracker.com/id/1040428" } ] } }