QID 980894

QID 980894: Java (maven) Security Update for org.apache.tomcat.embed:tomcat-embed-core (GHSA-r4x2-3cq5-hqvp)

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-r4x2-3cq5-hqvp for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980894

    Software Advisories
    Advisory ID Software Component Link
    GHSA-r4x2-3cq5-hqvp org.apache.tomcat.embed:tomcat-embed-core URL Logo github.com/advisories/GHSA-r4x2-3cq5-hqvp