CVE-2018-8020
tomcat-native: Mishandled OCSP responses can allow clients to authenticate with revoked certificates
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 has a flaw that does not properly check OCSP pre-produced responses, which are lists (multiple entries) of certificate statuses. Subsequently, revoked client certificates may not be properly identified, allowing for users to authenticate with revoked certificates to connections that require mutual TLS. Users not using OCSP checks are not affected by this vulnerability.
Apache Tomcat Native desde la versión 1.2.0 hasta la 1.2.16 y desde la versión 1.1.23 hasta la 1.1.34 tiene un error por el cual no comprueba las respuestas OCSP preproducidas, las cuales son listas (múltiples entradas) de estados de certificados. Subsecuentemente, los certificados de cliente revocados no se identifican correctamente, lo que permite que los usuarios se autentiquen con certificados revocados en conexiones que requieren TLS mutuo. Los usuarios que no emplean comprobaciones OCSP no se han visto afectados por esta vulnerabilidad.
When using pre-produced responses from an OCSP responder, Tomcat Native did not correctly validate the status of certificates. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-07-31 CVE Published
- 2024-09-17 CVE Updated
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
- CWE-295: Improper Certificate Validation
CAPEC
References (15)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2018:2469 | 2023-11-07 | |
https://access.redhat.com/errata/RHSA-2018:2470 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-8020 | 2018-08-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1581569 | 2018-08-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Native Search vendor "Apache" for product "Tomcat Native" | >= 1.1.23 <= 1.1.34 Search vendor "Apache" for product "Tomcat Native" and version " >= 1.1.23 <= 1.1.34" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Tomcat Native Search vendor "Apache" for product "Tomcat Native" | >= 1.2.0 <= 1.2.16 Search vendor "Apache" for product "Tomcat Native" and version " >= 1.2.0 <= 1.2.16" | - |
Affected
|