Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2017-5664 (High) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar #121

Open
mend-for-github-com bot opened this issue Nov 19, 2019 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource

Comments

@mend-for-github-com
Copy link
Contributor

mend-for-github-com bot commented Nov 19, 2019

CVE-2017-5664 - High Severity Vulnerability

Vulnerable Libraries - tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar

tomcat-catalina-7.0.42.jar

Tomcat Servlet Engine Core Classes and Standard implementations

Library home page: http://tomcat.apache.org/

Path to dependency file: /pom.xml

Path to vulnerable library: /repository/org/apache/tomcat/tomcat-catalina/7.0.42/tomcat-catalina-7.0.42.jar

Dependency Hierarchy:

  • tomcat-catalina-7.0.42.jar (Vulnerable Library)
tomcat-embed-core-8.0.18.jar

Core Tomcat implementation

Library home page: http://tomcat.apache.org/

Path to dependency file: /pom.xml

Path to vulnerable library: /repository/org/apache/tomcat/embed/tomcat-embed-core/8.0.18/tomcat-embed-core-8.0.18.jar

Dependency Hierarchy:

  • tomcat-embed-core-8.0.18.jar (Vulnerable Library)

Found in HEAD commit: 349fffeed7cf25f2cf5b8b6a05b5e4367130406e

Found in base branches: dev, master

Vulnerability Details

The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is presented to the error page with the original HTTP method. If the error page is a static file, expected behaviour is to serve content of the file as if processing a GET request, regardless of the actual HTTP method. The Default Servlet in Apache Tomcat 9.0.0.M1 to 9.0.0.M20, 8.5.0 to 8.5.14, 8.0.0.RC1 to 8.0.43 and 7.0.0 to 7.0.77 did not do this. Depending on the original request this could lead to unexpected and undesirable results for static error pages including, if the DefaultServlet is configured to permit writes, the replacement or removal of the custom error page. Notes for other user provided error pages: (1) Unless explicitly coded otherwise, JSPs ignore the HTTP method. JSPs used as error pages must must ensure that they handle any error dispatch as a GET request, regardless of the actual method. (2) By default, the response generated by a Servlet does depend on the HTTP method. Custom Servlets used as error pages must ensure that they handle any error dispatch as a GET request, regardless of the actual method.

Publish Date: 2017-06-06

URL: CVE-2017-5664

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5664

Release Date: 2017-06-06

Fix Resolution: 8.0.44


⛑️ Automatic Remediation is available for this issue

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by WhiteSource label Nov 19, 2019
@mend-for-github-com mend-for-github-com bot changed the title CVE-2017-5664 (High) detected in tomcat-embed-core-8.0.18.jar CVE-2017-5664 (High) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar Mar 25, 2021
@mend-for-github-com mend-for-github-com bot changed the title CVE-2017-5664 (High) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar CVE-2017-5664 (Medium) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar Oct 12, 2022
@mend-for-github-com mend-for-github-com bot changed the title CVE-2017-5664 (Medium) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar CVE-2017-5664 (High) detected in tomcat-catalina-7.0.42.jar, tomcat-embed-core-8.0.18.jar Dec 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by WhiteSource
Projects
None yet
Development

No branches or pull requests

0 participants