Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2018-1304 Details

Description

The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://access.redhat.com/errata/RHSA-2018:0465 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:0466 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:1320 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:1447 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2018:1448 CVEThird Party Advisory

see all 80 references

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-noinfoInsufficient Information to Classify Weakness[email protected]

Affected Products

ProductVersions

Change History

59 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2018-1304
NVD Published Date:
Feb 28, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2018-1304 Details - Not Deferred