Description
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Exploits (2)
References (40)
... and 20 more
Scores
CVSS v3
5.9
EPSS
0.0208
EPSS Percentile
84.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Lab Environment
Details
Status
published
Products (21)
apache/tomcat
8.0.0 rc1
apache/tomcat
9.0.0 milestone1 (27 CPE variants)
apache/tomcat
7.0.0 - 7.0.84
canonical/ubuntu_linux
14.04
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
17.10
canonical/ubuntu_linux
18.04
debian/debian_linux
7.0
debian/debian_linux
8.0
debian/debian_linux
9.0
... and 11 more
Published
Feb 28, 2018
Tracked Since
Feb 18, 2026