CVE-2018-8034 - High Severity Vulnerability
Vulnerable Library - tomcat-embed-websocket-8.5.16.jar
Core Tomcat implementation
Library home page: http://tomcat.apache.org/
Path to dependency file: /infiniboard/harvester/build.gradle
Path to vulnerable library: /root/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-websocket/8.5.16/8df572a6fa38c24a6366ab254b9bde496ed5ea95/tomcat-embed-websocket-8.5.16.jar,/root/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-websocket/8.5.16/8df572a6fa38c24a6366ab254b9bde496ed5ea95/tomcat-embed-websocket-8.5.16.jar
Dependency Hierarchy:
- spring-boot-starter-web-1.5.5.RELEASE.jar (Root Library)
- spring-boot-starter-tomcat-1.5.5.RELEASE.jar
- ❌ tomcat-embed-websocket-8.5.16.jar (Vulnerable Library)
Found in HEAD commit: 743bd280ef9d3a3127ed7f904cd5dddec872618a
Vulnerability Details
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Publish Date: 2018-08-01
URL: CVE-2018-8034
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8034
Release Date: 2018-01-07
Fix Resolution: 7.0.90, 8.0.53, 8.5.32, 9.0.10
Step up your Open Source Security Game with WhiteSource here
CVE-2018-8034 - High Severity Vulnerability
Core Tomcat implementation
Library home page: http://tomcat.apache.org/
Path to dependency file: /infiniboard/harvester/build.gradle
Path to vulnerable library: /root/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-websocket/8.5.16/8df572a6fa38c24a6366ab254b9bde496ed5ea95/tomcat-embed-websocket-8.5.16.jar,/root/.gradle/caches/modules-2/files-2.1/org.apache.tomcat.embed/tomcat-embed-websocket/8.5.16/8df572a6fa38c24a6366ab254b9bde496ed5ea95/tomcat-embed-websocket-8.5.16.jar
Dependency Hierarchy:
Found in HEAD commit: 743bd280ef9d3a3127ed7f904cd5dddec872618a
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Publish Date: 2018-08-01
URL: CVE-2018-8034
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
For more information on CVSS3 Scores, click here.Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8034
Release Date: 2018-01-07
Fix Resolution: 7.0.90, 8.0.53, 8.5.32, 9.0.10
Step up your Open Source Security Game with WhiteSource here