CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tomcat5.5 (Ubuntu) |
Invalid
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
Undecided
|
Tyler Hicks | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Maverick |
Invalid
|
Undecided
|
Unassigned | ||
Natty |
Invalid
|
Undecided
|
Unassigned | ||
Oneiric |
Invalid
|
Undecided
|
Unassigned | ||
tomcat6 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Undecided
|
Marc Deslauriers | ||
Lucid |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Maverick |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Natty |
Fix Released
|
Undecided
|
Marc Deslauriers | ||
Oneiric |
Fix Released
|
Undecided
|
Unassigned | ||
tomcat7 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Hardy |
Invalid
|
Undecided
|
Unassigned | ||
Lucid |
Invalid
|
Undecided
|
Unassigned | ||
Maverick |
Invalid
|
Undecided
|
Unassigned | ||
Natty |
Invalid
|
Undecided
|
Unassigned | ||
Oneiric |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
This CVE will impact pretty much every version of tomcat6 we currently support and tomcat7 in oneiric.
I'm working on a new upstream version of tomcat7 in debian and can do the same with tomcat6 for oneiric but the fix will need backporting to previous releases as well.
>>>>>>>>>>>>>>>>>
CVE-2011-3190 Apache Tomcat Authentication bypass and information disclosure
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
- Tomcat 7.0.0 to 7.0.20
- Tomcat 6.0.0 to 6.0.33
- Tomcat 5.5.0 to 5.5.33
- Earlier, unsupported versions may also be affected
Description:
Apache Tomcat supports the AJP protocol which is used with reverse
proxies to pass requests and associated data about the request from the
reverse proxy to Tomcat. The AJP protocol is designed so that when a
request includes a request body, an unsolicited AJP message is sent to
Tomcat that includes the first part (or possibly all) of the request
body. In certain circumstances, Tomcat did not process this message as a
request body but as a new request. This permitted an attacker to have
full control over the AJP message which allowed an attacker to (amongst
other things):
- insert the name of an authenticated user
- insert any client IP address (potentially bypassing any client IP
address filtering)
- trigger the mixing of responses between users
The following AJP connector implementations are not affected:
org.apache.
The following AJP connector implementations are affected:
org.apache.
org.apache.
org.apache.
Further, this issue only applies if all of the following are are true
for at least one resource:
- POST requests are accepted
- The request body is not processed
Example: See https:/
Mitigation:
Users of affected versions should apply one of the following mitigations:
- Upgrade to a version of Apache Tomcat that includes a fix for this
issue when available
- Apply the appropriate patch
- 7.0.x http://
- 6.0.x http://
- 5.5.x http://
- Configure the reverse proxy and Tomcat's AJP connector(s) to use the
requiredSecret attribute
- Use the org.apache.
available for Tomcat 7.0.x)
Credit:
The issue was reported via Apache Tomcat's public issue tracker.
The Apache Tomcat security team strongly discourages reporting of
undisclosed vulnerabilities via public channels. All Apache Tomcat
security vulnerabilities should be reported to the private security team
mailing list: <email address hidden>
References:
http://
http://
http://
http://
https:/
Related branches
- Dave Walker (community): Approve
- Ubuntu branches: Pending requested
-
Diff: 2811 lines (+2710/-9)9 files modified.pc/0013-CVE-2011-3190.patch/java/org/apache/coyote/ajp/AjpAprProcessor.java (+1337/-0)
.pc/0013-CVE-2011-3190.patch/java/org/apache/coyote/ajp/AjpProcessor.java (+1269/-0)
.pc/applied-patches (+1/-0)
debian/changelog (+6/-0)
debian/control (+2/-1)
debian/patches/0013-CVE-2011-3190.patch (+72/-0)
debian/patches/series (+1/-0)
java/org/apache/coyote/ajp/AjpAprProcessor.java (+11/-4)
java/org/apache/coyote/ajp/AjpProcessor.java (+11/-4)
visibility: | private → public |
Changed in tomcat6 (Ubuntu Hardy): | |
status: | In Progress → Invalid |
Changed in tomcat6 (Ubuntu Lucid): | |
status: | In Progress → Fix Committed |
Changed in tomcat6 (Ubuntu Maverick): | |
status: | In Progress → Fix Committed |
Changed in tomcat6 (Ubuntu Natty): | |
status: | In Progress → Fix Committed |
Changed in tomcat5.5 (Ubuntu Hardy): | |
assignee: | nobody → Tyler Hicks (tyhicks) |
status: | Confirmed → In Progress |
New upstream release sync for tomcat7 raised under bug 844745