QID 980894
QID 980894: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-r4x2-3cq5-hqvp)
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r4x2-3cq5-hqvp for updates pertaining to this vulnerability.
Vendor References
- GHSA-r4x2-3cq5-hqvp -
github.com/advisories/GHSA-r4x2-3cq5-hqvp
CVEs related to QID 980894
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r4x2-3cq5-hqvp | org.apache.tomcat.embed:tomcat-embed-core |
|