UBUNTU-CVE-2017-7674

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2017-7674
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-7674.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-7674
Related
Published
2017-08-10T00:00:00Z
Modified
2017-08-10T00:00:00Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

References

Affected packages

Ubuntu:14.04:LTS / tomcat7

Package

Name
tomcat7
Purl
pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.13?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.52-1ubuntu0.13

Affected versions

7.*

7.0.42-1
7.0.47-1
7.0.50-1
7.0.52-1
7.0.52-1ubuntu0.1
7.0.52-1ubuntu0.3
7.0.52-1ubuntu0.6
7.0.52-1ubuntu0.7
7.0.52-1ubuntu0.8
7.0.52-1ubuntu0.9
7.0.52-1ubuntu0.10
7.0.52-1ubuntu0.11

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "tomcat7-examples": "7.0.52-1ubuntu0.13",
            "tomcat7-admin": "7.0.52-1ubuntu0.13",
            "tomcat7-user": "7.0.52-1ubuntu0.13",
            "libservlet3.0-java": "7.0.52-1ubuntu0.13",
            "libservlet3.0-java-doc": "7.0.52-1ubuntu0.13",
            "libtomcat7-java": "7.0.52-1ubuntu0.13",
            "tomcat7-docs": "7.0.52-1ubuntu0.13",
            "tomcat7": "7.0.52-1ubuntu0.13",
            "tomcat7-common": "7.0.52-1ubuntu0.13"
        }
    ]
}

Ubuntu:16.04:LTS / tomcat8

Package

Name
tomcat8
Purl
pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.5?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.32-1ubuntu1.5

Affected versions

8.*

8.0.26-1
8.0.28-1
8.0.30-1
8.0.32-1
8.0.32-1ubuntu1
8.0.32-1ubuntu1.1
8.0.32-1ubuntu1.2
8.0.32-1ubuntu1.3
8.0.32-1ubuntu1.4

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "tomcat8-common": "8.0.32-1ubuntu1.5",
            "tomcat8-admin": "8.0.32-1ubuntu1.5",
            "tomcat8-user": "8.0.32-1ubuntu1.5",
            "libtomcat8-java": "8.0.32-1ubuntu1.5",
            "tomcat8": "8.0.32-1ubuntu1.5",
            "tomcat8-examples": "8.0.32-1ubuntu1.5",
            "libservlet3.1-java-doc": "8.0.32-1ubuntu1.5",
            "libservlet3.1-java": "8.0.32-1ubuntu1.5",
            "tomcat8-docs": "8.0.32-1ubuntu1.5"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / tomcat7

Package

Name
tomcat7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7.*

7.0.64-1
7.0.68-1
7.0.68-1ubuntu0.1
7.0.68-1ubuntu0.3
7.0.68-1ubuntu0.4
7.0.68-1ubuntu0.4+esm1
7.0.68-1ubuntu0.4+esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:18.04:LTS / tomcat7

Package

Name
tomcat7
Purl
pkg:deb/ubuntu/tomcat7@7.0.78-1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.0.78-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libservlet3.0-java": "7.0.78-1",
            "libservlet3.0-java-doc": "7.0.78-1"
        }
    ]
}