CVE-2018-8037
Summary
| CVE | CVE-2018-8037 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-02 14:29:00 UTC |
| Updated | 2023-12-08 16:41:00 UTC |
| Description | If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Apache Tomcat NIO/NIO2 Connector Management Flaw Lets Remote Users Access Other User's Sessions in Certain Cases - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| July 2018 Apache Tomcat Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| CPU Oct 2018 |
CONFIRM |
www.oracle.com |
Patch, Third Party Advisory |
| Oracle Critical Patch Update - October 2019 |
MISC |
www.oracle.com |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Oracle Critical Patch Update Advisory - April 2020 |
N/A |
www.oracle.com |
|
| Apache Tomcat CVE-2018-8037 Information Disclosure Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Pony Mail! |
MLIST |
lists.apache.org |
|
| Pony Mail! |
|
lists.apache.org |
|
| Pony Mail! |
MLIST |
lists.apache.org |
Mailing List, Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Pony Mail! |
|
lists.apache.org |
|
| Debian -- Security Information -- DSA-4281-1 tomcat8 |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] CVE-2018-8037 Apache Tomcat - Information Disclosure |
MLIST |
mail-archives.us.apache.org |
Mailing List, Vendor Advisory |
| [UPDATE][SECURITY] CVE-2018-8037 Apache Tomcat - Information Disclosure |
MLIST |
mail-archives.us.apache.org |
Mailing List, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 940573 AlmaLinux Security Update for pki-deps:10.6 (ALSA-2019:1529)
- 960759 Rocky Linux Security Update for pki-deps:10.6 (RLSA-2019:1529)
- 981251 Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-6v52-mj5r-7j2m)