The host name verification missing in Apache Tomcat
High severity
GitHub Reviewed
Published
Oct 17, 2018
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Package
Affected versions
>= 9.0.0, <= 9.0.9
>= 8.5.0, < 8.5.32
>= 8.0.0, < 8.0.53
>= 7.0.35, <= 7.0.88
Patched versions
9.0.10
8.5.32
8.0.53
7.0.90
Description
Published by the National Vulnerability Database
Aug 1, 2018
Published to the GitHub Advisory Database
Oct 17, 2018
Reviewed
Jun 16, 2020
Last updated
Oct 21, 2024
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
References