Author: markt
Date: Wed Jan 26 11:10:26 2022
New Revision: 1897496
URL: http://svn.apache.org/viewvc?rev=1897496&view=rev
Log:
Publish details of CVE-2022-23181
Modified:
tomcat/site/trunk/docs/security-10.html
tomcat/site/trunk/docs/security-8.html
tomcat/site/trunk/docs/security-9.html
tomcat/site/trunk/xdocs/security-10.xml
tomcat/site/trunk/xdocs/security-8.xml
tomcat/site/trunk/xdocs/security-9.xml
Modified: tomcat/site/trunk/docs/security-10.html
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-10.html?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-10.html (original)
+++ tomcat/site/trunk/docs/security-10.html Wed Jan 26 11:10:26 2022
@@ -1,6 +1,6 @@
<!DOCTYPE html SYSTEM "about:legacy-compat">
<html lang="en"><head><META http-equiv="Content-Type" content="text/html;
charset=UTF-8"><meta name="viewport" content="width=device-width,
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet"
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet"
type="text/css"><title>Apache Tomcat® - Apache Tomcat 10
vulnerabilities</title><meta name="author" content="Apache Tomcat
Project"></head><body><div id="wrapper"><header id="header"><div
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div
class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img
class="tomcat-logo pull-left noPrint" alt="Tomcat Home"
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache
Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a
href="https://www.apache.org/foundation/contributing.html" target="_blank"
class="pull-left"><img
src="https://www.apache.org/images/SupportApache-small.png" class="support-asf"
alt="Support Apache"></a><a
href="http://www.apache.org/" target="_blank" class="pull-left"><img
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software
Foundation"></a></div></div></header><main id="middle"><div><div
id="mainLeft"><div id="nav-wrapper"><form
action="https://www.google.com/search" method="get"><div
class="searchbox"><input value="tomcat.apache.org" name="sitesearch"
type="hidden"><input aria-label="Search text" placeholder="Search…"
required="required" name="q" id="query"
type="search"><button>GO</button></div></form><nav><div><h2>Apache
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a
href="./whichversion.html">Which version?</a></li><li><a
href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a
href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a
href="https://tomcat.apache.org/downlo
ad-80.cgi">Tomcat 8</a></li><li><a
href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool
for Jakarta EE</a></li><li><a
href="https://tomcat.apache.org/download-connectors.cgi">Tomcat
Connectors</a></li><li><a
href="https://tomcat.apache.org/download-native.cgi">Tomcat
Native</a></li><li><a
href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a
href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a
href="./connectors-doc/">Tomcat Connectors</a></li><li><a
href="./native-doc/">Tomcat Native</a></li><li><a
href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a
href="./migration.html">Migration Guide</a></li><l
i><a href="./presentations.html">Presentations</a></li><li><a
href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
href="./security.html">Security Reports</a></li><li><a
href="./findhelp.html">Find help</a></li><li><a
href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a
href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug
Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get
Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a
href="./source.html">Source code</a></li><li><a
href="./ci.html">Buildbot</a></li><li><a
href="https://cwiki.apache.org/confluence/x/vIPzBQ">Translations</a></li><li><a
href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a
href="https://twitter.com/theapachetomcat">Twitter</a></li><li><a
href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li><li><a
href="https://b
logs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
href="./whoweare.html">Who We Are</a></li><li><a
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a
href="./heritage.html">Heritage</a></li><li><a
href="http://www.apache.org">Apache Home</a></li><li><a
href="./resources.html">Resources</a></li><li><a
href="./contact.html">Contact</a></li><li><a
href="./legal.html">Legal</a></li><li><a
href="https://www.apache.org/foundation/contributing.html">Support
Apache</a></li><li><a
href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a
href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a
href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div
id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in
Apache Tomcat 10.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat
10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache
Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in
Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed
in Apache Tomcat 10.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache Tomcat
10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in Apache
Tomcat 10.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in
Apache Tomcat 10.0.0-M10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M8">Fixed in Apache Tomcat
10.0.0-M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in
Apache Tomcat 10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.
0-M6">Fixed in Apache Tomcat 10.0.0-M6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat
10.0.0-M5</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a
vulnerability in Tomcat</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.16">Fixed in
Apache Tomcat 10.0.16</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M10">Fixed in Apache Tomcat
10.1.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.12">Fixed in
Apache Tomcat 10.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.1.0-M6">Fixed in Apache Tomcat
10.1.0-M6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.7">Fixed in Apache
Tomcat 10.0.7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.6">Fixed in
Apache Tomcat 10.0.6</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.5">Fixed
in Apache Tomcat 10.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.4">Fixed in Apache Tomcat
10.0.4</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.2">Fixed in Apache
Tomcat 10.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M10">Fixed in
Apache Tomcat 10.0.0-M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-
M8">Fixed in Apache Tomcat 10.0.0-M8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M7">Fixed in Apache Tomcat
10.0.0-M7</a></li><li><a href="#Fixed_in_Apache_Tomcat_10.0.0-M6">Fixed in
Apache Tomcat 10.0.0-M6</a></li><li><a
href="#Fixed_in_Apache_Tomcat_10.0.0-M5">Fixed in Apache Tomcat
10.0.0-M5</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a
vulnerability in Tomcat</a></li></ul>
</div><h3 id="Apache_Tomcat_10.x_vulnerabilities">Apache Tomcat 10.x
vulnerabilities</h3><div class="text">
<p>This page lists all security vulnerabilities fixed in released versions
of Apache Tomcat 10.x. Each vulnerability is given a
@@ -37,6 +37,58 @@
<a href="security.html">Tomcat Security Team</a>. Thank you.
</p>
+ </div><h3 id="Fixed_in_Apache_Tomcat_10.0.16"><span class="pull-right">20
January 2022</span> Fixed in Apache Tomcat 10.0.16</h3><div class="text">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.15 but the
+ release vote for the 10.0.15 release candidate did not pass. Therefore,
+ although users must download 10.0.16 to obtain a version that includes a
+ fix for these issues, version 10.0.15 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181"
rel="nofollow">CVE-2022-23181</a></p>
+
+ <p>The fix for bug <a
href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484"
rel="nofollow">CVE-2020-9484</a> introduced a time of check, time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/094800b12d6c958d7b4540372c5a95698658ada1">094800b1</a>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 10.0.0-M5 to 10.0.14</p>
+
+ </div><h3 id="Fixed_in_Apache_Tomcat_10.1.0-M10"><span class="pull-right">20
January 2022</span> Fixed in Apache Tomcat 10.1.0-M10</h3><div class="text">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 10.1.0-M9 but the
+ release vote for the 10.1.0-M9 release candidate did not pass.
Therefore,
+ although users must download 10.1.0-M10 to obtain a version that
includes a
+ fix for these issues, version 10.1.0-M9 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181"
rel="nofollow">CVE-2022-23181</a></p>
+
+ <p>The fix for bug <a
href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484"
rel="nofollow">CVE-2020-9484</a> introduced a time of check, time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/70da1aaa51e0f9d088438e9d958812a144e12754">70da1aaa</a>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.0-M8</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_10.0.12"><span class="pull-right">1
October 2021</span> Fixed in Apache Tomcat 10.0.12</h3><div class="text">
<p><strong>Important: Denial of Service</strong>
Modified: tomcat/site/trunk/docs/security-8.html
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-8.html?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-8.html (original)
+++ tomcat/site/trunk/docs/security-8.html Wed Jan 26 11:10:26 2022
@@ -1,6 +1,6 @@
<!DOCTYPE html SYSTEM "about:legacy-compat">
<html lang="en"><head><META http-equiv="Content-Type" content="text/html;
charset=UTF-8"><meta name="viewport" content="width=device-width,
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet"
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet"
type="text/css"><title>Apache Tomcat® - Apache Tomcat 8
vulnerabilities</title><meta name="author" content="Apache Tomcat
Project"></head><body><div id="wrapper"><header id="header"><div
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div
class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img
class="tomcat-logo pull-left noPrint" alt="Tomcat Home"
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache
Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a
href="https://www.apache.org/foundation/contributing.html" target="_blank"
class="pull-left"><img
src="https://www.apache.org/images/SupportApache-small.png" class="support-asf"
alt="Support Apache"></a><a h
ref="http://www.apache.org/" target="_blank" class="pull-left"><img
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software
Foundation"></a></div></div></header><main id="middle"><div><div
id="mainLeft"><div id="nav-wrapper"><form
action="https://www.google.com/search" method="get"><div
class="searchbox"><input value="tomcat.apache.org" name="sitesearch"
type="hidden"><input aria-label="Search text" placeholder="Search…"
required="required" name="q" id="query"
type="search"><button>GO</button></div></form><nav><div><h2>Apache
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a
href="./whichversion.html">Which version?</a></li><li><a
href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a
href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a
href="https://tomcat.apache.org/downloa
d-80.cgi">Tomcat 8</a></li><li><a
href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool
for Jakarta EE</a></li><li><a
href="https://tomcat.apache.org/download-connectors.cgi">Tomcat
Connectors</a></li><li><a
href="https://tomcat.apache.org/download-native.cgi">Tomcat
Native</a></li><li><a
href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a
href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a
href="./connectors-doc/">Tomcat Connectors</a></li><li><a
href="./native-doc/">Tomcat Native</a></li><li><a
href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a
href="./migration.html">Migration Guide</a></li><li
><a href="./presentations.html">Presentations</a></li><li><a
>href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
> href="./security.html">Security Reports</a></li><li><a
>href="./findhelp.html">Find help</a></li><li><a
>href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a
> href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug
>Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get
>Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a
>href="./source.html">Source code</a></li><li><a
>href="./ci.html">Buildbot</a></li><li><a
>href="https://cwiki.apache.org/confluence/x/vIPzBQ">Translations</a></li><li><a
> href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a
>href="https://twitter.com/theapachetomcat">Twitter</a></li><li><a
>href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li><li><a
>href="https://bl
ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
href="./whoweare.html">Who We Are</a></li><li><a
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a
href="./heritage.html">Heritage</a></li><li><a
href="http://www.apache.org">Apache Home</a></li><li><a
href="./resources.html">Resources</a></li><li><a
href="./contact.html">Contact</a></li><li><a
href="./legal.html">Legal</a></li><li><a
href="https://www.apache.org/foundation/contributing.html">Support
Apache</a></li><li><a
href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a
href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a
href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div
id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.72">Fixed in
Apache Tomcat 8.5.72</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.68">Fixed
in Apache Tomcat 8.5.68</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.66">Fixed in Apache Tomcat
8.5.66</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.65">Fixed in Apache
Tomcat 8.5.65</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.64">Fixed in
Apache Tomcat 8.5.64</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.63">Fixed
in Apache Tomcat 8.5.63</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.60">Fixed in Apache Tomcat
8.5.60</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.58">Fixed in Apache
Tomcat 8.5.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.57">Fixed in
Apache Tomcat 8.5.57</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.56">Fixed
in Apache Tomcat 8.5.56</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.55">Fixed in Apache Tomcat 8.5.
55</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.51">Fixed in Apache Tomcat
8.5.51</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.50">Fixed in Apache
Tomcat 8.5.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.49">Fixed in
Apache Tomcat 8.5.49</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.41">Fixed
in Apache Tomcat 8.5.41</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.40">Fixed in Apache Tomcat
8.5.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.38">Fixed in Apache
Tomcat 8.5.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.34">Fixed in
Apache Tomcat 8.5.34</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.53">Fixed
in Apache Tomcat 8.0.53</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.32">Fixed in Apache Tomcat
8.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.52">Fixed in Apache
Tomcat 8.0.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.31">Fixed in
Apache Tomcat 8.5.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.50">Fixed
in Apache Tomcat 8.0.5
0</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.28">Fixed in Apache Tomcat
8.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.48">Fixed in Apache
Tomcat 8.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.24">Fixed in
Apache Tomcat 8.5.24</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.47">Fixed
in Apache Tomcat 8.0.47</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.23">Fixed in Apache Tomcat
8.5.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.45">Fixed in Apache
Tomcat 8.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.16">Fixed in
Apache Tomcat 8.5.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.44">Fixed
in Apache Tomcat 8.0.44</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.15">Fixed in Apache Tomcat
8.5.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.43">Fixed in Apache
Tomcat 8.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.13">Fixed in
Apache Tomcat 8.5.13</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.42">Fixed
in Apache Tomcat 8.0.42
</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.12">Fixed in Apache Tomcat
8.5.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.41">Fixed in Apache
Tomcat 8.0.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.11">Fixed in
Apache Tomcat 8.5.11</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.9">Fixed
in Apache Tomcat 8.5.9</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.39">Fixed in Apache Tomcat
8.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.8">Fixed in Apache
Tomcat 8.5.8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.5_and_8.0.37">Fixed in Apache Tomcat 8.5.5
and 8.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.3_and_8.0.36">Fixed
in Apache Tomcat 8.5.3 and 8.0.36</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.32">Fixed in Apache Tomcat
8.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.30">Fixed in Apache
Tomcat 8.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.27">Fixed in
Apache Tomcat 8.0.27</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.
0.17">Fixed in Apache Tomcat 8.0.17</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.9">Fixed in Apache Tomcat
8.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.8">Fixed in Apache
Tomcat 8.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.5">Fixed in
Apache Tomcat 8.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.3">Fixed
in Apache Tomcat 8.0.3</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.0-RC10">Fixed in Apache Tomcat
8.0.0-RC10</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC3">Fixed in
Apache Tomcat 8.0.0-RC3</a></li><li><a
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in
Tomcat</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability
in Tomcat</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.75">Fixed in
Apache Tomcat 8.5.75</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.72">Fixed
in Apache Tomcat 8.5.72</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.68">Fixed in Apache Tomcat
8.5.68</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.66">Fixed in Apache
Tomcat 8.5.66</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.65">Fixed in
Apache Tomcat 8.5.65</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.64">Fixed
in Apache Tomcat 8.5.64</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.63">Fixed in Apache Tomcat
8.5.63</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.60">Fixed in Apache
Tomcat 8.5.60</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.58">Fixed in
Apache Tomcat 8.5.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.57">Fixed
in Apache Tomcat 8.5.57</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.56">Fixed in Apache Tomcat 8.5.
56</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.55">Fixed in Apache Tomcat
8.5.55</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.51">Fixed in Apache
Tomcat 8.5.51</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.50">Fixed in
Apache Tomcat 8.5.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.49">Fixed
in Apache Tomcat 8.5.49</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.41">Fixed in Apache Tomcat
8.5.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.40">Fixed in Apache
Tomcat 8.5.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.38">Fixed in
Apache Tomcat 8.5.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.34">Fixed
in Apache Tomcat 8.5.34</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.53">Fixed in Apache Tomcat
8.0.53</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.32">Fixed in Apache
Tomcat 8.5.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.52">Fixed in
Apache Tomcat 8.0.52</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.31">Fixed
in Apache Tomcat 8.5.3
1</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.50">Fixed in Apache Tomcat
8.0.50</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.28">Fixed in Apache
Tomcat 8.5.28</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.48">Fixed in
Apache Tomcat 8.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.24">Fixed
in Apache Tomcat 8.5.24</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.47">Fixed in Apache Tomcat
8.0.47</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.23">Fixed in Apache
Tomcat 8.5.23</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.45">Fixed in
Apache Tomcat 8.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.16">Fixed
in Apache Tomcat 8.5.16</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.44">Fixed in Apache Tomcat
8.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.15">Fixed in Apache
Tomcat 8.5.15</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.43">Fixed in
Apache Tomcat 8.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.13">Fixed
in Apache Tomcat 8.5.13
</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.42">Fixed in Apache Tomcat
8.0.42</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.12">Fixed in Apache
Tomcat 8.5.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.41">Fixed in
Apache Tomcat 8.0.41</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.11">Fixed
in Apache Tomcat 8.5.11</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.9">Fixed in Apache Tomcat
8.5.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.39">Fixed in Apache
Tomcat 8.0.39</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.8">Fixed in
Apache Tomcat 8.5.8</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.5.5_and_8.0.37">Fixed in Apache Tomcat 8.5.5
and 8.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.5.3_and_8.0.36">Fixed
in Apache Tomcat 8.5.3 and 8.0.36</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.32">Fixed in Apache Tomcat
8.0.32</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.30">Fixed in Apache
Tomcat 8.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.
0.27">Fixed in Apache Tomcat 8.0.27</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.17">Fixed in Apache Tomcat
8.0.17</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.9">Fixed in Apache
Tomcat 8.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.8">Fixed in
Apache Tomcat 8.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.5">Fixed
in Apache Tomcat 8.0.5</a></li><li><a
href="#Fixed_in_Apache_Tomcat_8.0.3">Fixed in Apache Tomcat
8.0.3</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC10">Fixed in Apache
Tomcat 8.0.0-RC10</a></li><li><a href="#Fixed_in_Apache_Tomcat_8.0.0-RC3">Fixed
in Apache Tomcat 8.0.0-RC3</a></li><li><a
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in
Tomcat</a></li><li><a href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability
in Tomcat</a></li></ul>
</div><h3 id="Apache_Tomcat_8.x_vulnerabilities">Apache Tomcat 8.x
vulnerabilities</h3><div class="text">
<p>This page lists all security vulnerabilities fixed in released versions
of Apache Tomcat 8.x. Each vulnerability is given a
@@ -42,6 +42,32 @@
<a href="security.html">Tomcat Security Team</a>. Thank you.
</p>
+ </div><h3 id="Fixed_in_Apache_Tomcat_8.5.75"><span class="pull-right">20
January 2022</span> Fixed in Apache Tomcat 8.5.75</h3><div class="text">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 8.5.74 but the
+ release vote for the 8.5.74 release candidate did not pass. Therefore,
+ although users must download 8.5.75 to obtain a version that includes a
+ fix for these issues, version 8.5.74 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181"
rel="nofollow">CVE-2022-23181</a></p>
+
+ <p>The fix for bug <a
href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484"
rel="nofollow">CVE-2020-9484</a> introduced a time of check, time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/97943959ba721ad5e8e8ba765a68d2b153348530">97943959</a>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 8.5.55 to 8.5.73</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_8.5.72"><span class="pull-right">6
October 2021</span> Fixed in Apache Tomcat 8.5.72</h3><div class="text">
<p><strong>Important: Denial of Service</strong>
Modified: tomcat/site/trunk/docs/security-9.html
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/docs/security-9.html?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/docs/security-9.html (original)
+++ tomcat/site/trunk/docs/security-9.html Wed Jan 26 11:10:26 2022
@@ -1,6 +1,6 @@
<!DOCTYPE html SYSTEM "about:legacy-compat">
<html lang="en"><head><META http-equiv="Content-Type" content="text/html;
charset=UTF-8"><meta name="viewport" content="width=device-width,
initial-scale=1"><link href="res/css/tomcat.css" rel="stylesheet"
type="text/css"><link href="res/css/fonts/fonts.css" rel="stylesheet"
type="text/css"><title>Apache Tomcat® - Apache Tomcat 9
vulnerabilities</title><meta name="author" content="Apache Tomcat
Project"></head><body><div id="wrapper"><header id="header"><div
class="clearfix"><div class="menu-toggler pull-left" tabindex="1"><div
class="hamburger"></div></div><a href="http://tomcat.apache.org/"><img
class="tomcat-logo pull-left noPrint" alt="Tomcat Home"
src="res/images/tomcat.png"></a><h1 class="pull-left">Apache
Tomcat<sup>®</sup></h1><div class="asf-logos pull-right"><a
href="https://www.apache.org/foundation/contributing.html" target="_blank"
class="pull-left"><img
src="https://www.apache.org/images/SupportApache-small.png" class="support-asf"
alt="Support Apache"></a><a h
ref="http://www.apache.org/" target="_blank" class="pull-left"><img
src="res/images/asf_logo.svg" class="asf-logo" alt="The Apache Software
Foundation"></a></div></div></header><main id="middle"><div><div
id="mainLeft"><div id="nav-wrapper"><form
action="https://www.google.com/search" method="get"><div
class="searchbox"><input value="tomcat.apache.org" name="sitesearch"
type="hidden"><input aria-label="Search text" placeholder="Search…"
required="required" name="q" id="query"
type="search"><button>GO</button></div></form><nav><div><h2>Apache
Tomcat</h2><ul><li><a href="./index.html">Home</a></li><li><a
href="./taglibs.html">Taglibs</a></li><li><a href="./maven-plugin.html">Maven
Plugin</a></li></ul></div><div><h2>Download</h2><ul><li><a
href="./whichversion.html">Which version?</a></li><li><a
href="https://tomcat.apache.org/download-10.cgi">Tomcat 10</a></li><li><a
href="https://tomcat.apache.org/download-90.cgi">Tomcat 9</a></li><li><a
href="https://tomcat.apache.org/downloa
d-80.cgi">Tomcat 8</a></li><li><a
href="https://tomcat.apache.org/download-migration.cgi">Tomcat Migration Tool
for Jakarta EE</a></li><li><a
href="https://tomcat.apache.org/download-connectors.cgi">Tomcat
Connectors</a></li><li><a
href="https://tomcat.apache.org/download-native.cgi">Tomcat
Native</a></li><li><a
href="https://tomcat.apache.org/download-taglibs.cgi">Taglibs</a></li><li><a
href="https://archive.apache.org/dist/tomcat/">Archives</a></li></ul></div><div><h2>Documentation</h2><ul><li><a
href="./tomcat-10.1-doc/index.html">Tomcat 10.1 (alpha)</a></li><li><a
href="./tomcat-10.0-doc/index.html">Tomcat 10.0</a></li><li><a
href="./tomcat-9.0-doc/index.html">Tomcat 9.0</a></li><li><a
href="./tomcat-8.5-doc/index.html">Tomcat 8.5</a></li><li><a
href="./connectors-doc/">Tomcat Connectors</a></li><li><a
href="./native-doc/">Tomcat Native</a></li><li><a
href="https://cwiki.apache.org/confluence/display/TOMCAT">Wiki</a></li><li><a
href="./migration.html">Migration Guide</a></li><li
><a href="./presentations.html">Presentations</a></li><li><a
>href="https://cwiki.apache.org/confluence/x/Bi8lBg">Specifications</a></li></ul></div><div><h2>Problems?</h2><ul><li><a
> href="./security.html">Security Reports</a></li><li><a
>href="./findhelp.html">Find help</a></li><li><a
>href="https://cwiki.apache.org/confluence/display/TOMCAT/FAQ">FAQ</a></li><li><a
> href="./lists.html">Mailing Lists</a></li><li><a href="./bugreport.html">Bug
>Database</a></li><li><a href="./irc.html">IRC</a></li></ul></div><div><h2>Get
>Involved</h2><ul><li><a href="./getinvolved.html">Overview</a></li><li><a
>href="./source.html">Source code</a></li><li><a
>href="./ci.html">Buildbot</a></li><li><a
>href="https://cwiki.apache.org/confluence/x/vIPzBQ">Translations</a></li><li><a
> href="./tools.html">Tools</a></li></ul></div><div><h2>Media</h2><ul><li><a
>href="https://twitter.com/theapachetomcat">Twitter</a></li><li><a
>href="https://www.youtube.com/c/ApacheTomcatOfficial">YouTube</a></li><li><a
>href="https://bl
ogs.apache.org/tomcat/">Blog</a></li></ul></div><div><h2>Misc</h2><ul><li><a
href="./whoweare.html">Who We Are</a></li><li><a
href="https://www.redbubble.com/people/comdev/works/30885254-apache-tomcat">Swag</a></li><li><a
href="./heritage.html">Heritage</a></li><li><a
href="http://www.apache.org">Apache Home</a></li><li><a
href="./resources.html">Resources</a></li><li><a
href="./contact.html">Contact</a></li><li><a
href="./legal.html">Legal</a></li><li><a
href="https://www.apache.org/foundation/contributing.html">Support
Apache</a></li><li><a
href="https://www.apache.org/foundation/sponsorship.html">Sponsorship</a></li><li><a
href="http://www.apache.org/foundation/thanks.html">Thanks</a></li><li><a
href="http://www.apache.org/licenses/">License</a></li></ul></div></nav></div></div><div
id="mainRight"><div id="content"><h2 style="display: none;">Content</h2><h3
id="Table_of_Contents">Table of Contents</h3><div class="text">
-<ul><li><a href="#Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.54">Fixed in
Apache Tomcat 9.0.54</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.48">Fixed
in Apache Tomcat 9.0.48</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.46">Fixed in Apache Tomcat
9.0.46</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.45">Fixed in Apache
Tomcat 9.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.44">Fixed in
Apache Tomcat 9.0.44</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.43">Fixed
in Apache Tomcat 9.0.43</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in Apache Tomcat
9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in Apache
Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed in
Apache Tomcat 9.0.37</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed
in Apache Tomcat 9.0.36</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in Apache Tomcat 9.0.
35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed in Apache Tomcat
9.0.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.30">Fixed in Apache
Tomcat 9.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed in
Apache Tomcat 9.0.29</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed
in Apache Tomcat 9.0.20</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed in Apache Tomcat
9.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in Apache
Tomcat 9.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed in
Apache Tomcat 9.0.12</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed
in Apache Tomcat 9.0.10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in Apache Tomcat
9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in Apache
Tomcat 9.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed in
Apache Tomcat 9.0.5</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed
in Apache Tomcat 9.0.2</a></l
i><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed in Apache Tomcat
9.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in Apache
Tomcat 9.0.0.M22</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed
in Apache Tomcat 9.0.0.M21</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in Apache Tomcat
9.0.0.M19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in
Apache Tomcat 9.0.0.M18</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in Apache Tomcat
9.0.0.M17</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in
Apache Tomcat 9.0.0.M15</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in Apache Tomcat
9.0.0.M13</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in
Apache Tomcat 9.0.0.M10</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in Apache Tomcat
9.0.0.M8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M3">Fixed in Apache
Tomcat 9.0.0.M3</a></li><li><a href="#Not_a_vulnerab
ility_in_Tomcat">Not a vulnerability in Tomcat</a></li></ul>
+<ul><li><a href="#Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x
vulnerabilities</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.58">Fixed in
Apache Tomcat 9.0.58</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.54">Fixed
in Apache Tomcat 9.0.54</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.48">Fixed in Apache Tomcat
9.0.48</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.46">Fixed in Apache
Tomcat 9.0.46</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.45">Fixed in
Apache Tomcat 9.0.45</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.44">Fixed
in Apache Tomcat 9.0.44</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.43">Fixed in Apache Tomcat
9.0.43</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.40">Fixed in Apache
Tomcat 9.0.40</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.38">Fixed in
Apache Tomcat 9.0.38</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.37">Fixed
in Apache Tomcat 9.0.37</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.36">Fixed in Apache Tomcat 9.0.
36</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.35">Fixed in Apache Tomcat
9.0.35</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.31">Fixed in Apache
Tomcat 9.0.31</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.30">Fixed in
Apache Tomcat 9.0.30</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.29">Fixed
in Apache Tomcat 9.0.29</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.20">Fixed in Apache Tomcat
9.0.20</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.19">Fixed in Apache
Tomcat 9.0.19</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.16">Fixed in
Apache Tomcat 9.0.16</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.12">Fixed
in Apache Tomcat 9.0.12</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.10">Fixed in Apache Tomcat
9.0.10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.9">Fixed in Apache
Tomcat 9.0.9</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.8">Fixed in
Apache Tomcat 9.0.8</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.5">Fixed
in Apache Tomcat 9.0.5</a><
/li><li><a href="#Fixed_in_Apache_Tomcat_9.0.2">Fixed in Apache Tomcat
9.0.2</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.1">Fixed in Apache
Tomcat 9.0.1</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M22">Fixed in
Apache Tomcat 9.0.0.M22</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M21">Fixed in Apache Tomcat
9.0.0.M21</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M19">Fixed in
Apache Tomcat 9.0.0.M19</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M18">Fixed in Apache Tomcat
9.0.0.M18</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M17">Fixed in
Apache Tomcat 9.0.0.M17</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M15">Fixed in Apache Tomcat
9.0.0.M15</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M13">Fixed in
Apache Tomcat 9.0.0.M13</a></li><li><a
href="#Fixed_in_Apache_Tomcat_9.0.0.M10">Fixed in Apache Tomcat
9.0.0.M10</a></li><li><a href="#Fixed_in_Apache_Tomcat_9.0.0.M8">Fixed in
Apache Tomcat 9.0.0.M8</a></li><li><a href="#Fixed_in_Apache_To
mcat_9.0.0.M3">Fixed in Apache Tomcat 9.0.0.M3</a></li><li><a
href="#Not_a_vulnerability_in_Tomcat">Not a vulnerability in
Tomcat</a></li></ul>
</div><h3 id="Apache_Tomcat_9.x_vulnerabilities">Apache Tomcat 9.x
vulnerabilities</h3><div class="text">
<p>This page lists all security vulnerabilities fixed in released versions
of Apache Tomcat 9.x. Each vulnerability is given a
@@ -37,6 +37,32 @@
<a href="security.html">Tomcat Security Team</a>. Thank you.
</p>
+ </div><h3 id="Fixed_in_Apache_Tomcat_9.0.58"><span class="pull-right">20
January 2022</span> Fixed in Apache Tomcat 9.0.58</h3><div class="text">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 9.0.57 but the
+ release vote for the 9.0.57 release candidate did not pass. Therefore,
+ although users must download 9.0.58 to obtain a version that includes a
+ fix for these issues, version 9.0.57 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-23181"
rel="nofollow">CVE-2022-23181</a></p>
+
+ <p>The fix for bug <a
href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9484"
rel="nofollow">CVE-2020-9484</a> introduced a time of check, time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <a
href="https://github.com/apache/tomcat/commit/1385c624b4a1e994426e810075c850edc38a700e">1385c624</a>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 9.0.35 to 9.0.56</p>
+
</div><h3 id="Fixed_in_Apache_Tomcat_9.0.54"><span class="pull-right">1
October 2021</span> Fixed in Apache Tomcat 9.0.54</h3><div class="text">
<p><strong>Important: Denial of Service</strong>
Modified: tomcat/site/trunk/xdocs/security-10.xml
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-10.xml?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-10.xml (original)
+++ tomcat/site/trunk/xdocs/security-10.xml Wed Jan 26 11:10:26 2022
@@ -50,6 +50,62 @@
</section>
+ <section name="Fixed in Apache Tomcat 10.0.16" rtext="20 January 2022">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 10.0.15 but the
+ release vote for the 10.0.15 release candidate did not pass. Therefore,
+ although users must download 10.0.16 to obtain a version that includes a
+ fix for these issues, version 10.0.15 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <cve>CVE-2022-23181</cve></p>
+
+ <p>The fix for bug <cve>CVE-2020-9484</cve> introduced a time of check,
time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="094800b12d6c958d7b4540372c5a95698658ada1"/>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 10.0.0-M5 to 10.0.14</p>
+
+ </section>
+
+ <section name="Fixed in Apache Tomcat 10.1.0-M10" rtext="20 January 2022">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 10.1.0-M9 but the
+ release vote for the 10.1.0-M9 release candidate did not pass.
Therefore,
+ although users must download 10.1.0-M10 to obtain a version that
includes a
+ fix for these issues, version 10.1.0-M9 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <cve>CVE-2022-23181</cve></p>
+
+ <p>The fix for bug <cve>CVE-2020-9484</cve> introduced a time of check,
time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="70da1aaa51e0f9d088438e9d958812a144e12754"/>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 10.1.0-M1 to 10.1.0-M8</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 10.0.12" rtext="1 October 2021">
<p><strong>Important: Denial of Service</strong>
Modified: tomcat/site/trunk/xdocs/security-8.xml
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-8.xml?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-8.xml (original)
+++ tomcat/site/trunk/xdocs/security-8.xml Wed Jan 26 11:10:26 2022
@@ -56,6 +56,34 @@
</section>
+ <section name="Fixed in Apache Tomcat 8.5.75" rtext="20 January 2022">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 8.5.74 but the
+ release vote for the 8.5.74 release candidate did not pass. Therefore,
+ although users must download 8.5.75 to obtain a version that includes a
+ fix for these issues, version 8.5.74 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <cve>CVE-2022-23181</cve></p>
+
+ <p>The fix for bug <cve>CVE-2020-9484</cve> introduced a time of check,
time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="97943959ba721ad5e8e8ba765a68d2b153348530"/>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 8.5.55 to 8.5.73</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 8.5.72" rtext="6 October 2021">
<p><strong>Important: Denial of Service</strong>
Modified: tomcat/site/trunk/xdocs/security-9.xml
URL:
http://svn.apache.org/viewvc/tomcat/site/trunk/xdocs/security-9.xml?rev=1897496&r1=1897495&r2=1897496&view=diff
==============================================================================
--- tomcat/site/trunk/xdocs/security-9.xml (original)
+++ tomcat/site/trunk/xdocs/security-9.xml Wed Jan 26 11:10:26 2022
@@ -50,6 +50,34 @@
</section>
+ <section name="Fixed in Apache Tomcat 9.0.58" rtext="20 January 2022">
+
+ <p><i>Note: The issue below was fixed in Apache Tomcat 9.0.57 but the
+ release vote for the 9.0.57 release candidate did not pass. Therefore,
+ although users must download 9.0.58 to obtain a version that includes a
+ fix for these issues, version 9.0.57 is not included in the list of
+ affected versions.</i></p>
+
+ <p><strong>Low: Local Privilege Escalation</strong>
+ <cve>CVE-2022-23181</cve></p>
+
+ <p>The fix for bug <cve>CVE-2020-9484</cve> introduced a time of check,
time
+ of use vulnerability that allowed a local attacker to perform actions
+ with the privileges of the user that the Tomcat process is using. This
+ issue is only exploitable when Tomcat is configured to persist sessions
+ using the FileStore.</p>
+
+ <p>This was fixed with commit
+ <hashlink hash="1385c624b4a1e994426e810075c850edc38a700e"/>.</p>
+
+ <p>This issue was reported to the Apache Tomcat Security team by Trung Pham
+ of Viettel Cyber Security on 10 December 2021. The issue was made public
+ on 26 January 2022.</p>
+
+ <p>Affects: 9.0.35 to 9.0.56</p>
+
+ </section>
+
<section name="Fixed in Apache Tomcat 9.0.54" rtext="1 October 2021">
<p><strong>Important: Denial of Service</strong>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]