[CLSA-2026:1777884162] Fix CVE(s): CVE-2018-8014
Type:
security
Severity:
Critical
Release date:
2026-05-04 08:42:46 UTC
Description:
* Fix build process: - debian/keystores/ca-cert.pem, ca.jks: regenerate self-signed test CA using the existing ca-key.pem (previous CA valid only until 21.03.2025). New validity: 21.04.2026 to 18.04.2036. - debian/keystores/localhost-cert.pem, localhost.jks, localhost-copy1.jks: re-issue against the new CA to keep the chain consistent. Existing localhost-key.pem is preserved. - debian/keystores/user1-cert.pem, user1.jks: re-issue against the new CA using the existing user1-key.pem (previous cert valid only until 21.03.2025). - debian/keystores/updating-certs.txt: refresh the procedure notes with current serials and expiry dates. * SECURITY UPDATE: Insecure default configuration of the CORS filter allowed cross-origin requests with credentials from any origin. The default settings enabled supportsCredentials alongside a wildcard allowedOrigins. Affects Apache Tomcat 7.0.41 to 7.0.88. - debian/patches/CVE-2018-8014.patch: Change default allowedOrigins to empty and default supportsCredentials to false in the CORS filter, reject the unsafe combination of supportsCredentials=true with allowedOrigins=* at configuration time, and simplify the handleSimpleCORS logic accordingly. Backport of upstream commit d83a76732e. Note: applications relying on the previous permissive defaults must configure the filter explicitly. - CVE-2018-8014
Updated packages:
  • libservlet3.0-java_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:9aba78a6a4ea8d918f55a2c7d816828041cbbe16
  • libservlet3.0-java-doc_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:28dd3c134e260809405bfa9a2f8acc73f330e5ad
  • libtomcat7-java_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:2e00423838c15f293980be772b14f986be6bac86
  • tomcat7_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:9b7d810105c2837d7136ef858e757c490046007d
  • tomcat7-admin_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:a7e75542dd88d4de5468d4de1ec95d50f53bac56
  • tomcat7-common_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:de26b5af5867804440d46323221ecb7469004e77
  • tomcat7-docs_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:5a7b8b3af31134b95105564c3875432d97190232
  • tomcat7-examples_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:19de674af6ba02b7fcd0b35b048551b73ade0cc7
  • tomcat7-user_7.0.68-1ubuntu0.4+tuxcare.els3_all.deb
    sha:4de427d778d3dbe1c9a52696ed10b63a1030c936
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.