peter bassill · operator
$ cve CVE-2018-8014 JSON

CVE-2018-8014

9.8
CRITICAL · CVSS 3.0 · EPSS 21.3% (pctl 98)

Patch early

EPSS 21.3% — above the 10% action threshold.

Description

The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default configuration. Therefore, it is expected that most users will not be impacted by this issue.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS21.31% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-1188
On CISA KEVno
Public exploitnone known
Published2018-05-16
Last modified2026-06-17

Affected (9)

VendorProduct
apachetomcat
canonicalubuntu linux
debiandebian linux
microsoftwindows
netapponcommand insight
netapponcommand unified manager
netapponcommand workflow automation
netappsnapcenter server
netappstorage automation store

References

→ the Explorer  ·  watch your stack  ·  NVD