On 31/05/2022 16:17, DeHaven, Jacob wrote:
In regards, to the Low: Apache Tomcat EncryptInterceptor DoSĀ 
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885 which is fixed in 
Apache Tomcat 9.0.63, it is being reporting as a Low vulnerability on the 
Apache Tomcat website but others (NIST, Tenable) are reporting this 
vulnerability as High as seen below. Could someone please elaborate on this and 
which one is correct?

CVSS scores are highly subjective which is why the Apache Tomcat project doesn't use them.

The Apache Tomcat project has no view on whether the quoted CVSS scores are "correct" or not. If other folks want to argue over them they are free to do so. We don't have an opinion and won't be getting involved.

The Apache Tomcat project rates vulnerabilities based on this scale:
https://tomcat.apache.org/security-impact.html

To be impacted by CVE-2022-29885 an installation needs to be:
a) using Tomcat's clustering
b) running the clustering over a network accessible to untrusted actors
c) using the EncryptInterceptor
d) expecting c) to be providing full protection for the risks associated
   with b)

The above requirements, particularly b), were viewed as sufficiently unlikely as to merit a rating of Low.

I'll note that any claim that Tomcat needs to be upgraded to address this vulnerability is complete and utter nonsense. The "fix" was to change the documentation to clarify the limitations of the EncryptInterceptor.

If all of the requirements above apply then the recommendation would be to switch to a trusted network, e.g. by implementing IPSec for the clustering traffic.

Mark



NIST:
https://nvd.nist.gov/vuln/detail/CVE-2022-29885
Base Score: 7.5 HIGH

Tenable:
https://www.tenable.com/cve/CVE-2022-29885
Severity: HIGH

Our setup:
Apache Tomcat version: 9.0.58
OS: MS Windows Server 2019
Configured within Cognos ReportNet

Thanks,
Jacob DeHaven



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to