imPC@ndo IT

Tracker / CVE-2018-8019

CVE-2018-8019

High 7.4

When using an OCSP responder Apache Tomcat Native 1.2.0 to 1.2.16 and 1.1.23 to 1.1.34 did not correctly handle invalid responses. This allowed for revoked client certificates to be incorrectly identified. It was therefore possible for users to authenticate with revoked certificates when using mutual TLS. Users not using OCSP checks are not affected by this vulnerability.

Affected products and versions

apache tomcat_native · 1.1.23 → 1.1.34
apache tomcat_native · 1.2.0 → 1.2.16
debian debian_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References