Cross-site scripting in Apache Tomcat - CVE-2019-0221
Published: May 30, 2019 / Updated: November 25, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data within SSI printenv command, when parsing URI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Example:
http://[host]/printenv.shtml?%3Cscript%3Ealert(%27xss%27)%3C/script%3E
Affected software
JBoss Enterprise Web Server
Amazon Linux AMI
Gentoo Linux
Fedora
Ubuntu
Opensuse
Dell Support Assist Enterprise
Oracle Business Intelligence Enterprise Edition
tomcat8 (Ubuntu package)
libservlet3.0-java (Ubuntu package)
libtomcat7-java (Ubuntu package)
tomcat7 (Ubuntu package)
tomcat
Oracle Database Server
How to mitigate CVE-2019-0221
Dell Support Assist Enterprise - update to 4.00.06.00
JBoss Enterprise Web Server - update to 5.2.0
tomcat8 (Ubuntu package) - addressed in versions 8.0.32-1ubuntu1.10, 8.5.39-1ubuntu1~18.04.3
libservlet3.0-java (Ubuntu package) - update to Ubuntu Pro
libtomcat7-java (Ubuntu package) - update to Ubuntu Pro
tomcat7 (Ubuntu package) - update to Ubuntu Pro
tomcat - addressed in versions 7.0.94-1.el6, 9.0.21-1.fc29, 9.0.21-1.fc30
Links to Public Exploits and PoC-codes
External References
- http://seclists.org/fulldisclosure/2019/May/50
- https://lists.apache.org/thread.html/6e6e9eacf7b28fd63d249711e9d3ccd4e0a83f556e324aee37be5a8c@%3Cannounce.tomcat.apache.org%3E
- http://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.19
- http://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.40
- http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.94
Related Security Bulletins
- Remote code execution in Apache Tomcat
- OpenSUSE Linux update for tomcat
- OpenSUSE Linux update for tomcat
- Amazon Linux AMI update for tomcat7
- Amazon Linux AMI update for tomcat8
- Ubuntu update for Tomcat
- Multiple vulnerabilities in Red Hat JBoss Web Server
- Multple vulnerabilities in Red Hat JBoss Web Server
- Multiple vulnerabilities in Oracle Database Server
- Gentoo update for Apache Tomcat
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Dell Support Assist Enterprise
- Ubuntu update for tomcat7
- Fedora 29 update for tomcat
- Fedora 30 update for tomcat
- Fedora EPEL 6 update for tomcat