On 31/05/2022 16:17, DeHaven, Jacob wrote:
In regards, to the Low: Apache Tomcat EncryptInterceptor DoSĀ
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29885 which is fixed in
Apache Tomcat 9.0.63, it is being reporting as a Low vulnerability on the
Apache Tomcat website but others (NIST, Tenable) are reporting this
vulnerability as High as seen below. Could someone please elaborate on this and
which one is correct?
CVSS scores are highly subjective which is why the Apache Tomcat project
doesn't use them.
The Apache Tomcat project has no view on whether the quoted CVSS scores
are "correct" or not. If other folks want to argue over them they are
free to do so. We don't have an opinion and won't be getting involved.
The Apache Tomcat project rates vulnerabilities based on this scale:
https://tomcat.apache.org/security-impact.html
To be impacted by CVE-2022-29885 an installation needs to be:
a) using Tomcat's clustering
b) running the clustering over a network accessible to untrusted actors
c) using the EncryptInterceptor
d) expecting c) to be providing full protection for the risks associated
with b)
The above requirements, particularly b), were viewed as sufficiently
unlikely as to merit a rating of Low.
I'll note that any claim that Tomcat needs to be upgraded to address
this vulnerability is complete and utter nonsense. The "fix" was to
change the documentation to clarify the limitations of the
EncryptInterceptor.
If all of the requirements above apply then the recommendation would be
to switch to a trusted network, e.g. by implementing IPSec for the
clustering traffic.
Mark
NIST:
https://nvd.nist.gov/vuln/detail/CVE-2022-29885
Base Score: 7.5 HIGH
Tenable:
https://www.tenable.com/cve/CVE-2022-29885
Severity: HIGH
Our setup:
Apache Tomcat version: 9.0.58
OS: MS Windows Server 2019
Configured within Cognos ReportNet
Thanks,
Jacob DeHaven
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]