MGASA-2018-0149

    Dashboard / Vulnerabilities / MGASA-2018-0149

    MGASA-2018-0149

    Published: 28 Feb 2018Last Modified: 16 Apr 2026

    Summary: Updated tomcat packages fix security vulnerabilities

    Details: In Tomcat 8.0.45, the description of the search algorithm used by the CGI Servlet to identify which script to execute was updated. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behavior of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behavior that was wrong and has been corrected (CVE-2017-15706). The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorized users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected (CVE-2018-1304). Security constraints defined by annotations of Servlets were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorized to access them (CVE-2018-1305).

    Affected packages

    Package

    Name: tomcat

    Purl: pkg:rpm/mageia/tomcat?arch=source&distro=mageia-6

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -8.0.50-1.mga6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High