CVE-2020-1938
Apache Tomcat Improper Privilege Management Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run Apache Tomcat, fix it now.
CISA required action: Apply updates per vendor instructions.
US federal civilian agencies must remediate by Mar 17, 2022.
Patch status
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
- Patch or advisory on lists.apache.org (opens in a new tab)
- Patch or advisory on lists.apache.org (opens in a new tab)
- Patch or advisory on lists.apache.org (opens in a new tab)
- Patch or advisory on oracle.com (opens in a new tab)
- Patch or advisory on oracle.com (opens in a new tab)
- Patch or advisory on oracle.com (opens in a new tab)
Description
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
Affected products
| Product | Vendor | Affected versions | Fixed in | Source |
|---|---|---|---|---|
| Apache Tomcat | Apache Software Foundation | >= 7.0.0, < 7.0.100; >= 8.5.0, < 8.5.51; >= 9.0.0, < 9.0.31 | 7.0.100; 8.5.51; 9.0.31 | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog.
Intelligence timeline
Developments from the last 30 days, newest first.
- CVSS scoredUpdateKEV
CVE-2020-1938 scored CVSS 9.8: Apache Tomcat, Apache Tomcat Improper Privilege Management Vulnerability
CISA lists this as exploited in the wild. Unpatched Tomcat systems are exposed to active attacks now.
Basis: NIST National Vulnerability Database
- Patch releasedUpdateKEV
Patch released for CVE-2020-1938: Apache Tomcat, Apache Tomcat Improper Privilege Management Vulnerability
An official fix is now available for Apache Tomcat. This vulnerability is being exploited, so apply it promptly.
Basis: NVD patch reference
1 earlier event is available with a subscription. See plans.
Coverage
We have not published a story about this vulnerability yet.
References
- nvd.nist.gov
- lists.opensuse.org
- lists.opensuse.org
- support.blackberry.com
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
