The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
{
"versions": [
{
"introduced": "7.0.35"
},
{
"last_affected": "7.0.88"
},
{
"introduced": "8.5.0"
},
{
"last_affected": "8.5.31"
},
{
"introduced": "9.0.1"
},
{
"last_affected": "9.0.9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone10"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone11"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone12"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone13"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone14"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone15"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone16"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone17"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone18"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone19"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone20"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone21"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone22"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone23"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone24"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone25"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone26"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone27"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone3"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone4"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone5"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone6"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone7"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone8"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-milestone9"
},
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-8034.json"
[
{
"events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.0.52"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0.0-rc9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "5.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "15.0"
}
]
}
]