CVE-2017-7674

MEDIUM

Apache Tomcat <9.0.0.M21,8.5.15,8.0.44,7.0.78 - Info Disclosure

Title source: llm
STIX 2.1

Description

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

References (29)

Core 29
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1801
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180614-0003/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100280
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-3974
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2018/06/msg00008.html
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1802
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:3081

Scores

CVSS v3 4.3
EPSS 0.0592
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

CWE
CWE-345
Status published
Products (47)
apache/tomcat 7.0.41
apache/tomcat 7.0.42
apache/tomcat 7.0.43
apache/tomcat 7.0.44
apache/tomcat 7.0.45
apache/tomcat 7.0.46
apache/tomcat 7.0.47
apache/tomcat 7.0.48
apache/tomcat 7.0.49
apache/tomcat 7.0.50
... and 37 more
Published Aug 11, 2017
Tracked Since Feb 18, 2026